Photo by Christina @ wocintechchat.com on Unsplash. Source: https://unsplash.com/photos/woman-standing-near-wall-b6dfPNHa81w (Unsplash License).

Executive Summary

IDC Frontier, a SoftBank subsidiary, says a ransomware attack that began at about 3:40 a.m. local time on 7 October stopped virtual servers across four zones of its IDCF Cloud platform in East Japan Region 1. Data held in those zones cannot be extracted or restored. It counts 495 affected corporate and municipal customers. A day later the service was still down, with no recovery date.

Cloud ransomware recovery here rests on what customers hold themselves. IDC Frontier says the only reasonable path is a copy kept outside its infrastructure. MLex reported that at least one prefecture could not reach its own backup once the platform went dark. A snapshot inside the provider’s account is not a copy when the provider is the thing that failed.

The provider has published three bulletins in two days. A third party used ransomware, the affected zones went dark, and the data in them is not coming back through anything IDC Frontier controls.

IDCF Cloud runs public websites for Ibaraki Prefecture and its police force, the hardware behind Six Apart’s Movable Type cloud service, and the logistics system Nissui runs across 17 sites. When IDC Frontier cut the network, all of it stopped at once.

Diagram of two kinds of data copy. Inside the provider's failing administrative domain sit production virtual servers, provider-side snapshots and the management console, all lost together. Outside it sit a copy held under separate credentials and a tested restore, which survive the provider's failure.
Where a backup stops being a backup.

A console stopped in regions nobody touched

The company shut the customer management console in every region, not only the affected one, because that console is a single administrative surface for the whole estate. NHK World reported the outage reached customers outside the incident. A compromise in one region became a nationwide loss of control over systems no attacker had reached. It was the right call, and it still hurt.

One prefecture could not reach its own backup

The Asahi Shimbun reported the prefectural outages and the halted shipments at Nissui Logistics. The Mainichi reported that images claiming to come from the attacker were circulating and that IDC Frontier was still checking whether they were genuine. The attacker’s claims about data volume remain unverified.

Three questions worth answering this week. Where does your backup live, and under whose credentials? Can you restore it while your provider’s console is offline? And when did you last prove that answer instead of assuming it?

Related reading. When a hyperscaler told customers two regions were not coming back.

Sources. IDC Frontier incident bulletins, NHK World, The Asahi Shimbun, The Mainichi and MLex.

By Ivan Tarin

Ivan Tarin is a Principal Product Marketing Manager at SUSE, where he owns go-to-market strategy and positioning for a seven-product cloud-native portfolio spanning Kubernetes, virtualization, storage, security, and observability. A former full-stack developer who shipped production code for enterprise and public-sector clients including U.S. national laboratories, Ivan translates complex infrastructure and AI technology into messaging that lands with developers, platform teams, and enterprise buyers. He has presented at KubeCon, SUSECON, and AWS Developer Week, and is currently pursuing an MS in Artificial Intelligence at the University of Colorado Boulder.

One thought on “IDCF Cloud Told 495 Customers to Restore From Their Own Backups”

Leave a Reply

Your email address will not be published. Required fields are marked *

Get the next one before it is old news

Independent analysis of cloud-native infrastructure, Kubernetes and data center economics. No vendor spin.