LSN News › Singapore

Technology · Singapore Bureau

Japanese firms targeted in fresh Qilin ransomware campaign

At least 53 Japanese companies have fallen victim to the Qilin ransomware group, which has emerged as a significant threat to organizations across Asia and globally. The cybercriminal operation, active since October 2022, has targeted approximately 4,000 companies worldwide.

LSN Singapore · 8 October 2026

Japanese firms targeted in fresh Qilin ransomware campaign

The Qilin ransomware gang has ramped up attacks against Japanese enterprises, marking an escalation in its targeting of high-value victims across the region. Security researchers tracking the group's activities have documented dozens of Japanese organizations across various sectors being compromised in recent months.

Qilin, which commenced operations in mid-2022, has quickly established itself among the most prolific ransomware-as-a-service operations globally. The gang operates a sophisticated criminal enterprise, offering ransomware tools and infrastructure to affiliates who conduct the actual attacks and negotiations with victims.

The targeting of Japanese companies reflects the group's expansion beyond its initial focus areas. Like other major ransomware operations, Qilin typically exfiltrates sensitive data before encrypting systems, then demands payment in exchange for decryption keys and promises not to publish stolen information.

Organizations across Singapore and the region are being advised to strengthen their cybersecurity posture against such threats. Security experts recommend implementing robust backup systems, multi-factor authentication, and employee training programs to mitigate ransomware risks. Companies that fall victim are cautioned against paying ransoms, as doing so perpetuates the criminal ecosystem.