Skip to main content

Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use

0
High
Published: 09/17/2026 (09/17/2026, 10:00:43 UTC)
Source: Cisco Talos

Description

Ransomware incidents in Japan increased slightly by approximately 4.7% in the first half of 2026, with 90 organizations affected. The most active ransomware group was The Gentlemen, followed by Qilin, which is noted for leveraging AI to enhance its operations. Attackers primarily targeted small- and medium-sized enterprises, especially those with capital under JPY 1 billion, accounting for about 78% of victims. The manufacturing sector was the most affected industry. The Gentlemen operates via a Ransomware-as-a-Service model using a double-extortion strategy and has significantly increased its leak site activity. Investigations revealed The Gentlemen’s use of various tools for reconnaissance, exploitation, and network access, including exploits for CVE-2025-2479. The ransomware landscape in Japan is rapidly evolving with emerging groups requiring increased vigilance.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/17/2026, 10:13:22 UTC

Technical Analysis

In the first half of 2026, ransomware incidents in Japan rose slightly by 4.7%, with 90 reported cases. The Gentlemen ransomware group was the most active, responsible for 14 incidents, followed by Qilin and SafePay with seven incidents each. The Gentlemen employs a Ransomware-as-a-Service model and a double-extortion tactic, encrypting data and threatening to leak stolen information. Their leak site listings more than doubled from January to July 2026. The group targets mainly small- and medium-sized enterprises, particularly in manufacturing, professional services, and wholesale trade. Investigations uncovered The Gentlemen’s infrastructure, including tools for network tunneling, Active Directory reconnaissance, and exploitation of CVE-2025-2479, a SQL injection vulnerability. Qilin is notable for using AI to improve attack efficiency. The ransomware threat landscape in Japan is dynamic, with rapid changes in active groups and tactics.

Potential Impact

The ransomware activity continues to pose a significant threat to Japanese organizations, especially small- and medium-sized enterprises with capital under JPY 1 billion, which constitute the majority of victims. The manufacturing sector is the most affected industry. The Gentlemen’s use of double-extortion increases the risk of data leakage in addition to encryption. The rise in leak site listings indicates increased operational tempo and potential data exposure. The involvement of advanced tools and exploitation of known vulnerabilities like CVE-2025-2479 suggests sophisticated attack capabilities. Qilin’s use of AI may further enhance attack efficiency and effectiveness. The persistence and growth of these ransomware groups indicate ongoing risk to affected organizations.

Defensive Guidance

No specific patch or remediation is indicated for this threat report as it describes ransomware activity rather than a software vulnerability. Organizations should focus on ransomware defense best practices relevant to the described tactics, such as securing Active Directory, monitoring for exploitation of known vulnerabilities like CVE-2025-2479, and defending against network tunneling and credential relay attacks. Increased vigilance is advised against emerging groups like The Gentlemen and Qilin. Since this is a threat landscape report without direct vendor advisories or patches, check vendor advisories for updates on CVE-2025-2479 and related vulnerabilities. Incident response plans should consider the double-extortion tactics described.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.71,"severitySource":"heuristic","classifier":"rss-v2"}
Article Source
{"url":"https://blog.talosintelligence.com/ransomware-incidents-in-japan-in-the-first-half-of-2026/","fetched":true,"fetchedAt":"2026-09-17T10:13:17.619Z","wordCount":3017}

Threat ID: 6aabbd3d55bf5e2cf531b8c7

Added to database: 09/17/2026, 10:13:17 UTC

Last enriched: 09/17/2026, 10:13:22 UTC

Last updated: 09/17/2026, 23:02:41 UTC

Views: 13

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses