Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use
Ransomware incidents in Japan increased slightly by approximately 4.7% in the first half of 2026, with 90 organizations affected. The most active ransomware group was The Gentlemen, followed by Qilin, which is noted for leveraging AI to enhance its operations. Attackers primarily targeted small- and medium-sized enterprises, especially those with capital under JPY 1 billion, accounting for about 78% of victims. The manufacturing sector was the most affected industry. The Gentlemen operates via a Ransomware-as-a-Service model using a double-extortion strategy and has significantly increased its leak site activity. Investigations revealed The Gentlemen’s use of various tools for reconnaissance, exploitation, and network access, including exploits for CVE-2025-2479. The ransomware landscape in Japan is rapidly evolving with emerging groups requiring increased vigilance.
AI Analysis
Technical Summary
In the first half of 2026, ransomware incidents in Japan rose slightly by 4.7%, with 90 reported cases. The Gentlemen ransomware group was the most active, responsible for 14 incidents, followed by Qilin and SafePay with seven incidents each. The Gentlemen employs a Ransomware-as-a-Service model and a double-extortion tactic, encrypting data and threatening to leak stolen information. Their leak site listings more than doubled from January to July 2026. The group targets mainly small- and medium-sized enterprises, particularly in manufacturing, professional services, and wholesale trade. Investigations uncovered The Gentlemen’s infrastructure, including tools for network tunneling, Active Directory reconnaissance, and exploitation of CVE-2025-2479, a SQL injection vulnerability. Qilin is notable for using AI to improve attack efficiency. The ransomware threat landscape in Japan is dynamic, with rapid changes in active groups and tactics.
Potential Impact
The ransomware activity continues to pose a significant threat to Japanese organizations, especially small- and medium-sized enterprises with capital under JPY 1 billion, which constitute the majority of victims. The manufacturing sector is the most affected industry. The Gentlemen’s use of double-extortion increases the risk of data leakage in addition to encryption. The rise in leak site listings indicates increased operational tempo and potential data exposure. The involvement of advanced tools and exploitation of known vulnerabilities like CVE-2025-2479 suggests sophisticated attack capabilities. Qilin’s use of AI may further enhance attack efficiency and effectiveness. The persistence and growth of these ransomware groups indicate ongoing risk to affected organizations.
Mitigation Recommendations
No specific patch or remediation is indicated for this threat report as it describes ransomware activity rather than a software vulnerability. Organizations should focus on ransomware defense best practices relevant to the described tactics, such as securing Active Directory, monitoring for exploitation of known vulnerabilities like CVE-2025-2479, and defending against network tunneling and credential relay attacks. Increased vigilance is advised against emerging groups like The Gentlemen and Qilin. Since this is a threat landscape report without direct vendor advisories or patches, check vendor advisories for updates on CVE-2025-2479 and related vulnerabilities. Incident response plans should consider the double-extortion tactics described.
Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use
Description
Ransomware incidents in Japan increased slightly by approximately 4.7% in the first half of 2026, with 90 organizations affected. The most active ransomware group was The Gentlemen, followed by Qilin, which is noted for leveraging AI to enhance its operations. Attackers primarily targeted small- and medium-sized enterprises, especially those with capital under JPY 1 billion, accounting for about 78% of victims. The manufacturing sector was the most affected industry. The Gentlemen operates via a Ransomware-as-a-Service model using a double-extortion strategy and has significantly increased its leak site activity. Investigations revealed The Gentlemen’s use of various tools for reconnaissance, exploitation, and network access, including exploits for CVE-2025-2479. The ransomware landscape in Japan is rapidly evolving with emerging groups requiring increased vigilance.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In the first half of 2026, ransomware incidents in Japan rose slightly by 4.7%, with 90 reported cases. The Gentlemen ransomware group was the most active, responsible for 14 incidents, followed by Qilin and SafePay with seven incidents each. The Gentlemen employs a Ransomware-as-a-Service model and a double-extortion tactic, encrypting data and threatening to leak stolen information. Their leak site listings more than doubled from January to July 2026. The group targets mainly small- and medium-sized enterprises, particularly in manufacturing, professional services, and wholesale trade. Investigations uncovered The Gentlemen’s infrastructure, including tools for network tunneling, Active Directory reconnaissance, and exploitation of CVE-2025-2479, a SQL injection vulnerability. Qilin is notable for using AI to improve attack efficiency. The ransomware threat landscape in Japan is dynamic, with rapid changes in active groups and tactics.
Potential Impact
The ransomware activity continues to pose a significant threat to Japanese organizations, especially small- and medium-sized enterprises with capital under JPY 1 billion, which constitute the majority of victims. The manufacturing sector is the most affected industry. The Gentlemen’s use of double-extortion increases the risk of data leakage in addition to encryption. The rise in leak site listings indicates increased operational tempo and potential data exposure. The involvement of advanced tools and exploitation of known vulnerabilities like CVE-2025-2479 suggests sophisticated attack capabilities. Qilin’s use of AI may further enhance attack efficiency and effectiveness. The persistence and growth of these ransomware groups indicate ongoing risk to affected organizations.
Defensive Guidance
No specific patch or remediation is indicated for this threat report as it describes ransomware activity rather than a software vulnerability. Organizations should focus on ransomware defense best practices relevant to the described tactics, such as securing Active Directory, monitoring for exploitation of known vulnerabilities like CVE-2025-2479, and defending against network tunneling and credential relay attacks. Increased vigilance is advised against emerging groups like The Gentlemen and Qilin. Since this is a threat landscape report without direct vendor advisories or patches, check vendor advisories for updates on CVE-2025-2479 and related vulnerabilities. Incident response plans should consider the double-extortion tactics described.
Technical Details
- Classification
- {"confidence":0.71,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://blog.talosintelligence.com/ransomware-incidents-in-japan-in-the-first-half-of-2026/","fetched":true,"fetchedAt":"2026-09-17T10:13:17.619Z","wordCount":3017}
Threat ID: 6aabbd3d55bf5e2cf531b8c7
Added to database: 09/17/2026, 10:13:17 UTC
Last enriched: 09/17/2026, 10:13:22 UTC
Last updated: 09/17/2026, 23:02:41 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.