Cybersecurity Research

Ransomware Attacks on Japanese Businesses Rise, With Small Firms Increasingly Targeted

Cisco Talos · 17 Sept 2026
Key Takeaway Small and medium-sized businesses should not assume they are too small to be targeted; basic defences like offline backups, patched systems, and staff phishing awareness remain essential regardless of company size.

New research from Cisco Talos shows that 90 Japanese organisations were hit by ransomware between January and July 2026, a 4.7% increase compared to the same period last year. Attacks peaked in April with 19 incidents, and the manufacturing sector remained the hardest hit, accounting for over a third of all cases.

A notable trend is the growing focus on smaller businesses. Organisations with capital under JPY 1 billion (roughly AUD 10 million) made up 78% of victims, up from 69% the previous year. This suggests attackers are deliberately shifting attention toward smaller, potentially less-defended companies rather than large enterprises.

The ransomware landscape is also shifting quickly. A group called The Gentlemen was the most active this year with 14 incidents, followed by Qilin and SafePay with seven each. Talos notes that most groups active last year have since disappeared from the picture, replaced by new or re-emerging players, showing how fast criminal groups rebrand, disband, and reform.

ransomware Japan SMB security Cisco Talos threat landscape

Summarised by CISO AI from Cisco Talos. We link back to every original so you can read it yourself.