Full Breakdown
Qilin Ransomware Group Claims Cyberattack on Asahi Group Holdings
10/8/2025, 6:18:56 AM
Overview of the Cyberattack
On September 29, 2025, Japan's Asahi Group Holdings confirmed it had fallen victim to a ransomware attack attributed to the Qilin group, a Russian-speaking hacker collective. The attack disrupted operations at Asahi's six beer plants, leading to a suspension of production that lasted over a week. Asahi resumed production on October 2, but the full restoration of its systems remains uncertain.
Qilin claimed to have stolen approximately 27 gigabytes of data, including sensitive financial documents, contracts, and employee information, totaling 9,323 files. The group published 29 images on its website purportedly showing internal documents from Asahi. The authenticity of these documents has not been independently verified.
Impact on Operations
The cyberattack severely affected Asahi's distribution capabilities, forcing the company to process orders manually and halting most domestic production. Asahi's spokesperson indicated that the company is investigating the breach but declined to provide details about any ransom demands or negotiations with Qilin.
Experts have noted that the incident highlights Japan's vulnerability to cyber threats, particularly in its manufacturing sector, where disruptions can have significant ripple effects on supply chains. Takanori Nishiyama, a cybersecurity expert, emphasized that the attack underscores the need for enhanced cybersecurity measures in Japan's industrial landscape.
Official Statements & Responses
Asahi Group has acknowledged the cyberattack and is conducting an investigation to determine the extent of the data breach. The company initially reported that no personal or customer data was impacted, but subsequent updates indicated potential unauthorized data transfers. Asahi stated, "We are conducting an investigation to determine the nature and scope of the information that may have been subject to unauthorized transfer."
Criticism & Opposition
Critics have pointed out that the attack reflects a broader trend of increasing cyber threats targeting major corporations globally. The Qilin group has been linked to numerous high-profile attacks, including a $50 million ransomware incident involving the UK diagnostic services provider Synnovis, which had severe consequences for patient care.
Conflicting Reports & Gaps
While Qilin has claimed responsibility for the attack and detailed the data stolen, Asahi has not confirmed the specifics of the ransom demand or whether any negotiations took place. The timeline for the complete restoration of Asahi's systems remains unclear, and the company has not disclosed the potential financial impact of the cyberattack.
Verbatim Quotes
- “We are conducting investigation to determine the nature and scope of the information that may have been subject to unauthorised transfer,” Asahi said in its current update.” — Asahi Group Spokesperson
- “The Asahi incident is a clear reminder that operational resilience now depends on cyber security resilience, and that both must evolve together as Japan’s industrial sector continues its digital transformation.” — Takanori Nishiyama, SVP, APAC and Japan Country Manager at Keeper Security
What's Next
Asahi Group is in the process of gradually restoring operations while continuing its investigation into the cyberattack. The incident serves as a critical reminder for corporations to bolster their cybersecurity defenses against increasingly sophisticated ransomware threats.
