Ransomware Incidents in Japan Rise Slightly in Early 2026, Driven by The Gentlemen and Qilin Groups
Ransomware attacks in Japan saw a modest increase in the first half of 2026, with "The Gentlemen" and "Qilin" emerging as the most active threat actors, targeting SMEs and leveraging AI respectively.

Ransomware incidents in Japan experienced a slight uptick of approximately 4.7% in the first half of 2026 compared to the same period last year, underscoring the persistent and evolving threat posed by these attacks. Cisco Talos research indicates that 90 Japanese organizations fell victim to ransomware between January and July 2026, a marginal increase from the 86 incidents recorded in the prior year. The monthly average hovered around 13 incidents, with a notable peak in April.
"The Gentlemen" ransomware group was identified as the most active threat actor in Japan during this period, accounting for 14 reported incidents. This group, active since mid-2025, has been expanding its reach through a Ransomware-as-a-Service (RaaS) model and employs a double-extortion strategy. Their activity has significantly increased, with listings on their data leak site more than doubling from 48 in January to 105 in July. There are also indications of potential Russian-speaking involvement within "The Gentlemen" operations.
Following closely behind, "Qilin" ransomware was responsible for the second-highest number of observed incidents. Notably, "Qilin" is reportedly leveraging artificial intelligence (AI) to enhance the efficiency and effectiveness of its ransomware operations. This marks a significant development in the sophistication of ransomware tactics, as threat actors increasingly integrate advanced technologies into their attack methodologies.
The primary targets for ransomware attacks in Japan continue to be small and medium-sized enterprises (SMEs). Organizations with a capital of less than JPY 1 billion constituted approximately 80% of the total victims, an increase of around 13% from the previous year. This trend suggests a strategic shift by attackers to focus on entities that may possess fewer resources for robust cybersecurity defenses.
Industry-wise, the manufacturing sector remained the most heavily impacted, accounting for 34% of all ransomware incidents. The information and communications sector followed at 11%, with the services sector at 9%. These sectors are often attractive targets due to the critical nature of their operations and the potential for significant disruption.
The ransomware landscape in Japan is characterized by rapid change, with many groups observed in the first half of 2026 being different from those active in the same period last year. Beyond "The Gentlemen" and "Qilin," other observed ransomware types included SafePay, NightSpire, NetRunner, LockBit 5.0, RansomEXX, Stormous, and AiLock. This constant flux necessitates continuous vigilance and adaptation from cybersecurity defenders.
While the majority of incidents affected domestic Japanese organizations, 13.3% involved overseas offices and subsidiaries. Taiwan reported the highest number of these international incidents, followed by the United States and the Philippines. This global reach highlights the borderless nature of cyber threats and the need for coordinated international defense strategies.