On September 29, 2025, Asahi Group Holdings, which commands approximately 40% of Japan's beer market, fell victim to a massive ransomware attack. The attack paralyzed the company's order and shipping systems, forcing the temporary shutdown of operations at around 30 domestic factories.

The damage extended into the crucial year-end sales season, with Asahi Beer's October-December sales falling nearly 20% compared to the same period a year earlier. The attack struck during the most important period for the beer industry, the oseibo (year-end gift-giving) season and the height of end-of-year party celebrations.

Timeline and Impact of the Cyberattack

Discovery and Initial Response

Around 7:00 AM on September 29, 2025, anomalies were detected in Asahi Group Holdings' systems. Investigation revealed that the attack was orchestrated by Qilin, a Russian-speaking hacker group known for ransomware operations. The group issued a statement claiming responsibility on October 7, asserting they had stolen approximately 27 gigabytes of data.

Asahi Group immediately established an Emergency Response Headquarters and disconnected affected systems to prevent further damage. This action resulted in a complete halt to order and shipping operations across their beer, beverage, and food divisions.

Business Impact

The attack's effects were far-reaching across multiple business segments.

Sales Impact (Year-over-Year Comparison)

  • Asahi Beer: Just under 20% decline (October-December cumulative)
  • Asahi Soft Drinks: Approximately 30% decline (October-December cumulative)
  • Asahi Group Foods: Approximately 10% decline (October-December cumulative)

The quarter proved particularly damaging. Despite the approaching New Year holiday, a peak demand season, the company was forced to delay shipments and restrict sales of year-end gift sets, leaving Asahi Beer's October-December sales down just under 20% year-over-year.

Potential Data Breach

At a press conference on November 27, Asahi Group disclosed that personal information of approximately 1.914 million individuals may have been compromised. This included data from approximately 1.52 million customers who had contacted customer service centers, approximately 275,000 current and former employees and their family members, and roughly 114,000 external business contacts.

Ripple Effects Across the Industry

Impact on Competitors

Asahi's shipping delays, affecting roughly 40% of Japan's beer market, triggered a chain reaction throughout the industry.

The surge in demand for alternative products forced Kirin Beer, Suntory, and Sapporo Breweries to temporarily restrict shipments of certain products. Each company canceled or limited sales of year-end beer gift sets and suspended launches of seasonal limited-edition products.

In October, combined beer sales volume for the three major competitors (excluding Asahi) increased 18% year-over-year. Kirin Beer's "Ichiban Shibori" and other flagship brands recorded strong sales during the shortage.

Impact on Distribution and Retail

Convenience stores and restaurants in Tokyo experienced prolonged shortages of Asahi products. Some restaurants, working through wholesalers, switched their draft beer taps and glassware to Sapporo and Kirin brands, raising concerns about long-term erosion of brand loyalty that took decades to build.

The State of Japanese Corporate Cybersecurity

Rising Ransomware Threats

According to the Information-technology Promotion Agency (IPA)'s "Top 10 Information Security Threats 2025," ransomware attacks have ranked first for ten consecutive years. The first half of 2025 saw a record 116 ransomware incidents reported domestically, with small and medium enterprises accounting for 77 cases, about two-thirds of all incidents.

Police agency surveys indicate that over 80% of ransomware infections occur via VPN devices or remote desktop connections, highlighting security vulnerabilities that have emerged with the proliferation of remote work.

Japan-Specific Challenges

Experts point to several structural issues in Japanese corporate cybersecurity practices.

Declining Language Barrier Protection: Japanese companies were once relatively insulated from overseas hackers due to the language barrier, but advances in AI technology have rapidly eroded this protection.

Lack of Practical Experience: Having experienced relatively few major attacks in the past, many Japanese companies lack expertise in responding to cyber incidents.

Talent Shortage: Japan faces a severe supply-demand gap in cybersecurity professionals, with training programs failing to keep pace with needs.

Legacy System Issues: Many companies continue operating with inadequately integrated legacy systems inherited through mergers and acquisitions, creating security vulnerabilities.

Asahi Group's Response and Prevention Measures

System Recovery Efforts

Asahi Group began gradually resuming system-based order processing in December, aiming to normalize logistics operations by February 2026. The recovery plan, requiring approximately five months from the initial attack, underscores the severity of the damage.

President Atsushi Katsugi reflected at a press conference that "this was a preventable attack" and emphasized the critical importance of executive-level engagement in cybersecurity matters.

Enhanced Security Measures

The company is implementing the following measures:

  • Fundamental review and upgrade of security systems
  • Strengthened collaboration with external security experts
  • Comprehensive security education for all employees
  • Development of business continuity plans (BCP) for incident response

Lessons for Businesses

The attack on Asahi Group serves as a wake-up call for all Japanese corporations.

Recognition as a Management Issue: Cybersecurity is not merely an IT department concern but a risk fundamental to business operations that requires board-level attention.

Business Continuity Planning: Alternative measures and manual operation capabilities when systems fail are essential preparations.

Supply Chain-Wide Protection: Security measures must extend beyond the company itself to encompass the entire supply chain, including business partners.

Timely Disclosure: Transparent information sharing during incidents is crucial for maintaining stakeholder trust.

For Japanese companies to remain competitive in the global marketplace, investment in cybersecurity infrastructure and talent development is essential. How are companies in your country addressing cybersecurity measures and responding to large-scale cyberattacks? We'd love to hear your thoughts and experiences.

References