ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Askul confirms theft of 740,000 customer records in October ransomware attack

Japanese e-commerce company Askul Corporation has confirmed that approximately 740,000 customer records were stolen during a ransomware attack that disrupted its systems in October, causing prolonged operational outages and shipment delays that continue into mid-December.


Askul, a major business-to-business and business-to-consumer office supplies and logistics e-commerce provider owned by Yahoo! Japan Corporation, disclosed that the cyberattack led to widespread IT system failures and forced the suspension of shipments to customers, including retail chain Muji. The company said investigations into the scope and impact of the incident have now been completed.


The compromised data includes customer and partner information, though Askul said specific details are being withheld to prevent further exploitation. Affected customers and business partners will be notified individually. The company has also notified Japan’s Personal Information Protection Commission of the data exposure and has implemented long-term monitoring measures to detect potential misuse of the stolen information.


Operational disruptions remain ongoing. As of Dec. 15, order shipping continues to be affected while recovery efforts are underway to fully restore internal systems.


The attack has been claimed by the RansomHouse extortion group, which publicly disclosed the breach on Oct. 30 and later released data in two separate leaks on Nov. 10 and Dec. 2. Askul confirmed that the attackers both encrypted systems and exfiltrated data, resulting in system failures across multiple environments.


Askul said the breach began with the compromise of authentication credentials belonging to an outsourced partner’s administrator account that did not have multi-factor authentication enabled. After gaining initial access, the attackers conducted network reconnaissance, attempted to harvest additional credentials, disabled security controls such as endpoint detection and response software, and moved laterally across multiple servers to escalate privileges.


The company stated that multiple ransomware variants were used in the attack, including strains that evaded updated EDR signatures at the time. The ransomware payload was deployed simultaneously across several servers, and backup files were deliberately deleted to hinder recovery efforts.


In response to the incident, Askul physically disconnected infected networks, severed communications between data centers and logistics facilities, isolated affected devices, and updated security signatures. Multi-factor authentication has since been applied to all critical systems, and passwords for all administrator accounts have been reset.


Askul said the financial impact of the ransomware attack has not yet been determined. The company has postponed its scheduled earnings report to allow time for a comprehensive assessment of the damage and associated costs.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543