Japan Cyber Threat Intelligence Weekly (Apr 12–18, 2026) | Ransomware, ASKUL Breach, APT40 Activity
- Apr 21
- 2 min read
01 EXECUTIVE SUMMARY
Japan's threat posture during April 12–18, 2025, is assessed as ELEVATED. Three concurrent risk drivers were observed: active ransomware campaigns by Akira and LockBit 3.0 using novel IoT pivot techniques; a major confirmed data breach at ASKUL Corporation affecting approximately 2.5 million customer records; and sustained APT40 (China) intrusion activity targeting Japanese defense supply chain organizations. Initial Access Broker (IAB) listings on major dark web forums increased 18% week-over-week, predominantly covering manufacturing, logistics, and healthcare sectors.
Key developments:
ASKUL Corporation data breach — ~2.5M records exposed; METI notified; APPI 72-hour notification window applies.
Akira ransomware adopting IoT/webcam pivot to bypass EDR — confirmed against Japanese manufacturing firm.
NTT breach-linked phishing campaign active — AiTM infrastructure (Evilginx2) bypassing standard TOTP MFA.
APT40 targeting defense-industrial base with SOGU implant via CVE-2024-38214 weaponised DOCX attachments.
Panasonic GENESIS64 SCADA vulnerability (CVSS 7.2) with no available patch poses OT/ICS risk.
02 DARK WEB INTELLIGENCE
Japan-tagged listings on darkweb.vc increased approximately 18% compared to the prior week. The manufacturing and logistics sectors represent 60% of listings. Database and credential sales dominate — consistent with a post-breach monetisation phase aligned with the ASKUL incident timeline.

03 RANSOMWARE ACTIVITY

04 INITIAL ACCESS BROKER (IAB)
Sources: analyzer.vecert.io, darkweb.vc — Japan-region IAB listings April 12–18, 2025


05 SECURITY INCIDENTS


06 PHISHING & SOCIAL ENGINEERING TRENDS

07 APT / STATE ACTOR ACTIVITY


08 VULNERABILITY INTELLIGENCE


09 RECOMMENDATIONS


010 Unit Zero THREAT FORECAST
Outlook for the coming 7–14 days based on current threat actor behaviour patterns and intelligence trends.

011 What PIPELINE Inc. Can Do
In such a multifaceted threat landscape, “continuous visibility” and “risk-based prioritization” are essential, in addition to individual countermeasures. PIPELINE Inc. (Unit Zero Threat Intelligence Team), a cyber threat intelligence firm specializing in the Asia-Pacific region, offers the following support:
① Visualization of Externally Exposed Assets (Attack Surface Management)
Continuously monitor the exposure of your company’s domains and IP ranges to the internet. Early detection of unintentionally exposed servers (e.g., ComfyUI-like servers), IoT devices, and unpatched Citrix systems.
② Risk-Based Prioritization
Identify high-risk assets specific to the manufacturing, logistics, and defense supply chains (e.g., GPU servers, OT/ICS, VPN endpoints) and clarify response priorities.
③ Continuous Monitoring and Real-Time Alerts
24/7 monitoring of IAB lists on the dark web, ransomware leak sites, phishing domains targeting Japan, and APT activities. Immediate notification of signs of secondary attacks related to ASKUL/NTT.
④ Operationally Focused Countermeasure Design and Threat Hunting
Security design that does not compromise on-site convenience (FIDO2 implementation support, OT network segmentation, EDR optimization). Proactive threat hunting conducted as needed.
⑤ Regular delivery of weekly and monthly “Japan Threat Digest” reports
We continuously deliver customized versions of this report tailored specifically to your company’s environment. We can also provide executive summaries for management.
PIPELINE’s services cover everything from ‘prevention’ to “detection and response,” and we are particularly well-versed in regulatory compliance specific to Japanese companies (APPI, NISC reporting, MHLW notifications). Please contact us for details.
![[2nd Week of June 2026] From Zero-Day Attacks to State-Sponsored Attacks: 4 Latest Threats Targeting Japanese Companies PIPELINE](https://static.wixstatic.com/media/95ec1f_77789520e7b54469970eebdda4caea9c~mv2.png/v1/fill/w_366,h_250,fp_0.50_0.50,q_35,blur_30,enc_avif,quality_auto/95ec1f_77789520e7b54469970eebdda4caea9c~mv2.webp)
![[2nd Week of June 2026] From Zero-Day Attacks to State-Sponsored Attacks: 4 Latest Threats Targeting Japanese Companies PIPELINE](https://static.wixstatic.com/media/95ec1f_77789520e7b54469970eebdda4caea9c~mv2.png/v1/fill/w_980,h_670,fp_0.50_0.50,q_95,enc_avif,quality_auto/95ec1f_77789520e7b54469970eebdda4caea9c~mv2.webp)
![[5th Week of May 2026] Attacks are becoming more automated – 4 of the latest cyber threats targeting Japanese companies](https://static.wixstatic.com/media/95ec1f_13c273711c304fd2b2893f20be1f2e08~mv2.png/v1/fill/w_366,h_250,fp_0.50_0.50,q_35,blur_30,enc_avif,quality_auto/95ec1f_13c273711c304fd2b2893f20be1f2e08~mv2.webp)
![[5th Week of May 2026] Attacks are becoming more automated – 4 of the latest cyber threats targeting Japanese companies](https://static.wixstatic.com/media/95ec1f_13c273711c304fd2b2893f20be1f2e08~mv2.png/v1/fill/w_980,h_670,fp_0.50_0.50,q_95,enc_avif,quality_auto/95ec1f_13c273711c304fd2b2893f20be1f2e08~mv2.webp)
![[Week 3 of May 2026] Four New Threats Japanese Companies Should Be Wary of: Canvas breach, npm supply chain attack, and ClaudeBleed](https://static.wixstatic.com/media/95ec1f_f5d30c2fc79344eb8199da2390a2c1c3~mv2.png/v1/fill/w_366,h_250,fp_0.50_0.50,q_35,blur_30,enc_avif,quality_auto/95ec1f_f5d30c2fc79344eb8199da2390a2c1c3~mv2.webp)
![[Week 3 of May 2026] Four New Threats Japanese Companies Should Be Wary of: Canvas breach, npm supply chain attack, and ClaudeBleed](https://static.wixstatic.com/media/95ec1f_f5d30c2fc79344eb8199da2390a2c1c3~mv2.png/v1/fill/w_980,h_670,fp_0.50_0.50,q_95,enc_avif,quality_auto/95ec1f_f5d30c2fc79344eb8199da2390a2c1c3~mv2.webp)
![[2nd Week of June 2026] From Zero-Day Attacks to State-Sponsored Attacks: 4 Latest Threats Targeting Japanese Companies PIPELINE](https://static.wixstatic.com/media/95ec1f_77789520e7b54469970eebdda4caea9c~mv2.png/v1/fill/w_980,h_513,al_c,q_90,usm_0.66_1.00_0.01,enc_avif,quality_auto/95ec1f_77789520e7b54469970eebdda4caea9c~mv2.png)
![[5th Week of May 2026] Attacks are becoming more automated – 4 of the latest cyber threats targeting Japanese companies](https://static.wixstatic.com/media/95ec1f_13c273711c304fd2b2893f20be1f2e08~mv2.png/v1/fill/w_980,h_513,al_c,q_90,usm_0.66_1.00_0.01,enc_avif,quality_auto/95ec1f_13c273711c304fd2b2893f20be1f2e08~mv2.png)
![[Week 3 of May 2026] Four New Threats Japanese Companies Should Be Wary of: Canvas breach, npm supply chain attack, and ClaudeBleed](https://static.wixstatic.com/media/95ec1f_f5d30c2fc79344eb8199da2390a2c1c3~mv2.png/v1/fill/w_980,h_513,al_c,q_90,usm_0.66_1.00_0.01,enc_avif,quality_auto/95ec1f_f5d30c2fc79344eb8199da2390a2c1c3~mv2.png)
![[2nd Week of June 2026] From Zero-Day Attacks to State-Sponsored Attacks: 4 Latest Threats Targeting Japanese Companies PIPELINE](https://static.wixstatic.com/media/95ec1f_77789520e7b54469970eebdda4caea9c~mv2.png/v1/fill/w_444,h_250,fp_0.50_0.50,q_35,blur_30,enc_avif,quality_auto/95ec1f_77789520e7b54469970eebdda4caea9c~mv2.webp)
![[2nd Week of June 2026] From Zero-Day Attacks to State-Sponsored Attacks: 4 Latest Threats Targeting Japanese Companies PIPELINE](https://static.wixstatic.com/media/95ec1f_77789520e7b54469970eebdda4caea9c~mv2.png/v1/fill/w_385,h_217,fp_0.50_0.50,q_95,enc_avif,quality_auto/95ec1f_77789520e7b54469970eebdda4caea9c~mv2.webp)
![[5th Week of May 2026] Attacks are becoming more automated – 4 of the latest cyber threats targeting Japanese companies](https://static.wixstatic.com/media/95ec1f_13c273711c304fd2b2893f20be1f2e08~mv2.png/v1/fill/w_444,h_250,fp_0.50_0.50,q_35,blur_30,enc_avif,quality_auto/95ec1f_13c273711c304fd2b2893f20be1f2e08~mv2.webp)
![[5th Week of May 2026] Attacks are becoming more automated – 4 of the latest cyber threats targeting Japanese companies](https://static.wixstatic.com/media/95ec1f_13c273711c304fd2b2893f20be1f2e08~mv2.png/v1/fill/w_385,h_217,fp_0.50_0.50,q_95,enc_avif,quality_auto/95ec1f_13c273711c304fd2b2893f20be1f2e08~mv2.webp)
![[Week 3 of May 2026] Four New Threats Japanese Companies Should Be Wary of: Canvas breach, npm supply chain attack, and ClaudeBleed](https://static.wixstatic.com/media/95ec1f_f5d30c2fc79344eb8199da2390a2c1c3~mv2.png/v1/fill/w_444,h_250,fp_0.50_0.50,q_35,blur_30,enc_avif,quality_auto/95ec1f_f5d30c2fc79344eb8199da2390a2c1c3~mv2.webp)
![[Week 3 of May 2026] Four New Threats Japanese Companies Should Be Wary of: Canvas breach, npm supply chain attack, and ClaudeBleed](https://static.wixstatic.com/media/95ec1f_f5d30c2fc79344eb8199da2390a2c1c3~mv2.png/v1/fill/w_385,h_217,fp_0.50_0.50,q_95,enc_avif,quality_auto/95ec1f_f5d30c2fc79344eb8199da2390a2c1c3~mv2.webp)
![[Third Week of May 2026] Four Incidents at Japanese Companies: From GitHub Credential Leaks to Ransomware Attacks](https://static.wixstatic.com/media/95ec1f_e00e67a4854b4a8882a13950e4a7a324~mv2.png/v1/fill/w_444,h_250,fp_0.50_0.50,q_35,blur_30,enc_avif,quality_auto/95ec1f_e00e67a4854b4a8882a13950e4a7a324~mv2.webp)
![[Third Week of May 2026] Four Incidents at Japanese Companies: From GitHub Credential Leaks to Ransomware Attacks](https://static.wixstatic.com/media/95ec1f_e00e67a4854b4a8882a13950e4a7a324~mv2.png/v1/fill/w_385,h_217,fp_0.50_0.50,q_95,enc_avif,quality_auto/95ec1f_e00e67a4854b4a8882a13950e4a7a324~mv2.webp)
![[Week 2 of May 2026] Top 4 Cyber Threats Targeting Japanese Companies | npm Supply Chain Attacks, Fake AI Extensions & DNS Hijacking PIPELINE](https://static.wixstatic.com/media/95ec1f_df7cf37dcaa7470da1331eac6e21b25c~mv2.png/v1/fill/w_444,h_250,fp_0.50_0.50,q_35,blur_30,enc_avif,quality_auto/95ec1f_df7cf37dcaa7470da1331eac6e21b25c~mv2.webp)
![[Week 2 of May 2026] Top 4 Cyber Threats Targeting Japanese Companies | npm Supply Chain Attacks, Fake AI Extensions & DNS Hijacking PIPELINE](https://static.wixstatic.com/media/95ec1f_df7cf37dcaa7470da1331eac6e21b25c~mv2.png/v1/fill/w_385,h_217,fp_0.50_0.50,q_95,enc_avif,quality_auto/95ec1f_df7cf37dcaa7470da1331eac6e21b25c~mv2.webp)
![[April 4th Week, 2026] Top 3 Incidents at Japanese Companies: Simultaneous Multiple Attacks on Unauthorized Access, Ransomware, and Overseas Bases PIPELINE](https://static.wixstatic.com/media/95ec1f_d9fa7aad0cbd48fca7833df843dffbd0~mv2.png/v1/fill/w_444,h_250,fp_0.50_0.50,q_35,blur_30,enc_avif,quality_auto/95ec1f_d9fa7aad0cbd48fca7833df843dffbd0~mv2.webp)
![[April 4th Week, 2026] Top 3 Incidents at Japanese Companies: Simultaneous Multiple Attacks on Unauthorized Access, Ransomware, and Overseas Bases PIPELINE](https://static.wixstatic.com/media/95ec1f_d9fa7aad0cbd48fca7833df843dffbd0~mv2.png/v1/fill/w_385,h_217,fp_0.50_0.50,q_95,enc_avif,quality_auto/95ec1f_d9fa7aad0cbd48fca7833df843dffbd0~mv2.webp)