Published: · Region: East Asia · Category: cyber

Japan’s Ransomware Surge Exposes SME Weakness and Emerging AI‑Powered Criminal Tools

Ransomware attacks in Japan rose 4.7% in the first half of 2026, with one group more than doubling its leak‑site activity and another experimenting with AI to sharpen its operations. Small and mid‑sized firms account for 80% of victims, putting the backbone of Japan’s economy on the front line of an increasingly automated criminal ecosystem.

Japan’s small and mid‑sized companies are being dragged into a ransomware war they are poorly equipped to fight—and attackers are starting to bring artificial intelligence to the battlefield.

In the first half of 2026, recorded ransomware incidents in Japan increased by 4.7% year‑on‑year, according to incident data from private investigations and law enforcement. The group known as The Gentlemen emerged as the most active operator, with the number of organizations it listed on its public leak site more than doubling between January and July. Another crew, Qilin, ranked second and appeared to incorporate AI tools into its campaigns.

The pattern of victims is stark: roughly 80% were small and medium‑sized enterprises with capital under 1 billion yen. These firms often sit at the center of supply chains in manufacturing, logistics, healthcare and professional services. They manage sensitive customer data and proprietary designs but lack the dedicated security staff and budgets of Japan’s corporate giants.

When a ransomware gang hits a major automaker or electronics firm, it makes headlines and triggers a coordinated incident response. When the victim is a regional parts supplier or a small clinic, the impact can be just as severe—operations frozen, data locked, and weeks of downtime—but with far less outside support. For the owners and employees of those firms, a successful attack can mean missed payroll, breached client trust, or even insolvency.

The rise of The Gentlemen and Qilin shows how quickly this ecosystem evolves. The Gentlemen’s decision to more than double the number of victims it exposes publicly suggests a deliberate strategy to raise pressure on targets by maximizing reputational damage. Leak sites serve as both a shaming tool and a proof‑of‑work portfolio to attract new affiliates.

Qilin’s apparent use of AI is a different kind of warning. While technical specifics are still being examined, investigators have seen signs that the group is using AI models to assist with tasks such as customizing phishing lures in Japanese, automating parts of victim reconnaissance, or rapidly testing new obfuscation techniques. Early adoption of these tools means operators can run more campaigns, with more tailored social engineering, without proportionally increasing their manpower.

For Japan’s economy, the strategic risk goes beyond individual incidents. Supply chains are only as resilient as their weakest link; if a critical SME in a production network loses access to its systems, larger manufacturers can find entire lines disrupted. Repeated attacks also raise questions for foreign partners about data protection in joint ventures and outsourced operations.

There’s a broader global lesson in the numbers. Once AI becomes a standard part of criminal toolkits, the usual defenses—training staff to spot clumsy phishing emails, relying on known malware signatures—will catch less and less.

Key signals to watch include whether Japanese regulators and industry groups move to mandate stronger baseline security practices for SMEs, how quickly The Gentlemen and Qilin adapt their tactics when disrupted, and whether insurers start tightening coverage or raising premiums in response to the trend. Any confirmed evidence of AI being used not just for support tasks but to autonomously probe and exploit vulnerabilities would mark a new phase in how defenders have to think about speed and scale.

Sources