Threat Intelligence, Ransomware

Report: Ransomware targeting Japanese SMEs intensifies

(Adobe Stock)

Japan experienced a sharp rise in ransomware attacks during the first half of 2025, with 68 reported incidents, up 1.4 times from the same period last year, reports GBHackers News.

According to Cisco Talos, manufacturing was the most targeted sector at 18.2%, followed by automotive, trading, construction, and transportation industries. Small and medium-sized enterprises bore the majority of attacks, accounting for 69% of victims, reflecting their relative cybersecurity vulnerabilities. The ransomware landscape has shifted following the dismantling of dominant groups like LockBit and 8Base, making room for emerging actors. Qilin became the most prolific threat, claiming eight Japanese victims, while newcomers like Kawa4096 launched sophisticated campaigns using KaWaLocker ransomware. This malware employs advanced encryption, double-extortion tactics, selective file targeting, and post-encryption commands such as shadow deletion and system reboots. Cisco Talos noted that KaWaLocker 2.0 introduced obfuscation features, further complicating incident response. Experts urge Japanese SMEs to enhance vulnerability management, share threat intelligence, and remain vigilant against this evolving ransomware threat.

An In-Depth Guide to Ransomware

Get essential knowledge and practical strategies to protect your organization from ransomware attacks.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds