Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

IDC Frontier, the operator of IDCF Cloud, says a third-party ransomware attack disrupted virtual servers in four zones of East Japan Region 1: tesla, henry, pascal, and joule. The disruption began at about 03:40 JST on Wednesday, October 7, 2026. In its October 8 update, the company counted 495 companies and local governments as affected customers. Servers in those zones stopped, customers could not restart them, and the company said data in those zones appeared difficult to retrieve or restore. Its stated recovery path is restoration from backups that customers hold themselves.

What happened, in order

  1. Early October 7, 2026: The disruption started at about 03:40 JST, which IDC Frontier attributes to a third-party ransomware attack.
  2. October 7 containment: The company isolated East Japan Region 1 from its network and stopped systems there to limit secondary harm and possible data leakage.
  3. October 7 reporting: IDC Frontier says it reported the incident to supervisory authorities and the Tokyo Metropolitan Police.
  4. October 8 update: The company narrowed the confirmed affected area to four zones in East Japan Region 1, said it was preparing separate environments for affected customers to rebuild, and advised customers to restore from their own backups.

The company said it was still working to identify and block the intrusion route. It also said it was investigating networks, servers, and storage across its east and west Japan regions with an external security specialist, and that it was considering measures to prevent a recurrence.

Which zones and regions are affected

The October 8 update separates confirmed impact from precautionary action. The table below uses the company’s own categories. Only the first row describes confirmed disruption.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Zone or region Status stated in the October 8 update Restoration timing
tesla, henry, pascal, joule (East Japan Region 1) Affected. Virtual servers stopped and could not be restarted by customers. Data appeared difficult to retrieve or restore. Not stated in the October 8 notice
radian, newton (East Japan Region 1) Named as other zones in the same region. The company had not confirmed unauthorized access as of October 8. Not stated
East Japan Region 2 and East Japan Region 3 No unauthorized access confirmed as of October 8. External management-console access was suspended while safety was checked. Not stated
West Japan Region 1 No unauthorized access confirmed as of October 8. External management-console access was suspended while safety was checked. Not stated

The console suspension is a precaution outside the affected region. It should not be read as confirmed compromise of those regions.

#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

What customers can do now

IDC Frontier’s stated position is narrow, and customers should act on it directly. The following checks follow from the October 8 update:

  • Confirm your zone. Find out whether your virtual servers run in tesla, henry, pascal, or joule. Those zones are the only ones the company describes as disrupted.
  • Check whether you hold a usable backup. The company’s view is that data restoration is possible only from backup data customers hold themselves. If you have no current copy outside IDCF Cloud, the update offers no other recovery route.
  • Plan a rebuild, not a restart. The company said it is preparing separate environments for affected customers to rebuild in. Restarting the existing servers was not possible at the time of the update.
  • Expect limited console access outside the affected region. If your workloads sit in another zone, external management-console access may be unavailable while the company checks safety.

Because the notice gives no restoration date, customers should not plan around an expected return-to-service time based on the update alone.

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

Were government customers affected?

Yes, local governments are among the 495 customers the company counted as affected. The company’s count combines companies and local governments, and the October 8 notice does not break the figure down by sector or name individual customers. Any statement about a specific public body should come from that body or from the company, not from this count.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Downstream services and their own status reports

Several companies that depend on IDCF Cloud have published their own notices. Each reflects only that company’s services, so none can stand in for the status of other IDCF customers.

Rank #3
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
  • Nova System said in an October 7 notice that its AI facial-recognition access-control system and reception-terminal service were unavailable because of the IDCF Cloud incident. It said the impact on customer information was still being checked. This is a customer report, not confirmation of a personal-data breach.
  • Intercom said in an October 8 notice that information leakage had not been confirmed at that time, and it listed eight of its products as operating normally.
  • FiberGate reported that IDCF described ransomware against its management infrastructure and that network isolation and virtual-machine shutdown were emergency measures.
  • ITmedia reported outages affecting IDCF customers and public-facing services. It also noted that attribution to IDCF had not been publicly established for some of the examples it cited, so broader outage claims should be read with that limit.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What is still unknown

The October 8 notice does not establish the following. Until the company publishes further findings, treat each point as open:

  • Initial access route: The company was still identifying and blocking the intrusion path.
  • Attacker and ransomware strain: Neither was named in the notice.
  • Data theft: The notice did not say whether customer data was copied out. Reports should neither claim that data was stolen nor claim that it was not.
  • Full impact scope: Investigation of the detailed impact across all regions was continuing.
  • Recovery outcome: No restoration date was given for the affected zones or for the management console.

The company’s own wording on recovery is the most important line in the notice. In its October 8 Japanese announcement, IDC Frontier stated:

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display

「現時点での当社の見解では、データの復元はお客さま自身が保持しているバックアップデータからのみ可能となります。」

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In English, this reads roughly: “Based on the company’s current view, data restoration will be possible only from backup data that customers themselves hold.” This is an official corporate statement; the notice names no individual speaker.

What to watch next

The next confirmations that matter are the company’s findings on the intrusion route, any statement on whether customer data was copied, a restoration timeline for tesla, henry, pascal, and joule, and whether the precautionary console restrictions are lifted. Each would change a different part of this picture, so readers should check the date of any update they rely on.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.