ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Hunters International ransomware group demands a $10m ransom from Hoya Corporation

The Hunters International ransomware group has reportedly asked Japanese lensmaker Hoya Corporation to pay a ransom of $10 million after it compromised some of the company’s servers and allegedly stole up to 2 terabytes of data.

 

The Tokyo-based company, which ranks among the world’s largest manufacturers of lenses and other optical gear, said that it detected suspicious activity in the internal network of one of its overseas facilities on March 30 and immediately launched an investigation to determine the scope of the incident.

 

Hoya said it isolated the failed servers from the larger network and reported the matter to the relevant authorities in the affected countries. External cyber security experts who assisted the company’s investigation determined that the incident was most likely caused by unauthorised access to the company’s servers by a third party.

 

“While the full effects, extent and nature of the incident continue to be investigated, the systems for some production plants and the ordering system for several products have been affected. The Company is making every effort to respond to customer demand and minimise the impact on our customers to the greatest extent possible.

 

“We are also investigating whether any confidential or personal information held by the Company has been compromised or accessed by third parties, but the full analysis is expected to take a considerable number of days,” the company said.

 

“We will continue to investigate and analyse the impact of this incident in cooperation with outside experts and relevant authorities, and will take measures to restore the systems necessary for production and sales activities and to resume the supply system of products to customers as soon as possible,” it added.

 

Recently, French IT news site LeMagIT reported that the Hunters International ransomware group has demanded a $10 million ransom from Hoya to not publish an alleged 1.7 million stolen files, amounting to 2 terabytes of data. It has shared screenshots from the ransomware group’s negotiation panel that victims use to negotiate ransom payment.

 

The group has not claimed the cyber attack on Hoya publicly and is yet to release the stolen files on the dark web.

 

According to Hoya’s last update on the data security incident, it was assessing the situation for any material impact on its business performance and assured its customers that it will share more information about the incident as and when available. Hoya’s consumer eyeglass lens unit, Hoya Vision Care Co, apologised to customers for pausing order bookings for lenses due to a group-wide system failure.

 

Hoya suffered a major data security incident in 2019 as well that involved threat actors targeting a production facility in Thailand. This forced the company to take its production plant offline for three days. In 2021, the company suffered another cyber attack that affected its US systems.

 

A group of threat actors, going by the name Astro Team gang, claimed responsibility for the 2021 cyber attack on Hoya and listed the company as a victim on its dark web site. The group said that it stole around 300GB of data from the company, including data on finance, production, email and passwords, safety reports, clients’ data and more.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543