A drinks maker in Toyama was hit by ransomware in January 2026 and got its data back without paying a yen. What broke the encryption was a tool Japan's National Police Agency built itself.
The Police Called to Say the Files Were Coming Back
Tombow Beverage employs about 180 people. Shigeru Funaki, 56, who runs the company's IT section, noticed something wrong on the morning of January 15, 2026. The wallpaper on his screen had been altered, and the system that manages every employee terminal would not start.
Officers from the Toyama prefectural police came out, and together they opened one of the files on screen. Your data is encrypted, it said; pay, and it will be restored and the leak prevented. It was a claim of responsibility from LockBit, the international ransomware group.
Nine months of purchasing data had gone dark. Staff pulled out paper invoices and retyped raw-material transactions into the accounting software, night after night. Then, in late February, the police called: the files could be recovered. Funaki told the Yomiuri Shimbun he was glad the company had gone to the police.
The way in came out later. In the final report Tombow Beverage published in March, the entry point was remote desktop software reachable from the open internet. In the NPA's own survey, most intrusions arrive through remote-access equipment left reachable from outside the company.
The Police Had Built a Decryptor
It began when the NPA joined the international investigation into LockBit. An investigator in the agency's cyber special investigation department identified the builder that generated the ransomware, took it apart, and worked out how the encrypted files were structured.
In December 2023, the agency handed the tool it had developed to Europol. Domestic use started in February 2024. Since then the data of 41 Japanese companies, in manufacturing, retail and other sectors, has been brought back: about 20 million files, including customer lists and employee rosters. Using it costs nothing, and it is now in use in more than 100 countries.
The other end of that work is better known outside Japan. In February 2024, Operation Cronos, led by Britain's National Crime Agency, seized LockBit's servers. The LockBit 3.0 Black decryptor published at that moment on No More Ransom, the victim-facing portal, was developed by the Japanese police together with the NCA and the FBI, with support from Europol.
The same department later cracked files encrypted by Phobos and 8Base, working from information the FBI had obtained. That tool went up on the NPA's own website in July 2025 and has been downloaded more than 10,000 times. There is no application and no case number. You take it off the page.
But This Is Not a Cure-All
Japanese police logged 226 ransomware cases in 2025 alone. The 41 recoveries are a cumulative total since the tool went into domestic use, which makes them a small share of the damage.
What it can open is limited as well. Recovery works where investigators got hold of the builder and understood how the encryption had been implemented. Plenty of ransomware families never give them that opening.
Getting the data back is also not the same as getting the company back. In the NPA's own figures, more than half of the organisations hit spent at least 10 million yen (about $65,000) on recovery, and only a little over half were running again within a month. Closing the way in, replacing equipment and explaining yourself to customers all come after the decryption.
The other side has not stopped either. LockBit did not vanish with the 2024 takedown. According to Check Point, its successor LockBit 5.0 relaunched on an underground forum in September 2025 and listed 163 victims between January and March 2026. Qilin listed the most in the same quarter at 338, and the total across all groups was 2,122. The people breaking the encryption and the people rewriting it are moving at the same speed.
What Sits Behind a Country That Does Not Pay
That Japanese companies pay ransoms far less often than their peers abroad is something we looked at earlier. It usually gets explained as policy or culture: a decision not to fund criminals, held company-wide.
Whether a company can afford to refuse, though, depends on what is left after it refuses. That going to the police can actually end in decryption is part of that arithmetic, and it can be read as one of the things holding the refusal in place. Forty-one companies cannot account for a national payment rate. At Tombow Beverage, it settled the question.
If You Get Hit, Call the Police First
What the NPA asks for is plain: talk to the police before paying anyone. If the family is one they can break, the files come back. If it is not, at least the money never reaches the attacker.
Who would a company in your country call after an attack like this? Do the police there investigate and nothing more, or do they also sit on the side that breaks the encryption?
References
- https://news.yahoo.co.jp/articles/d6658df889e00fab6affbfc93a9794336efa0c25
- https://www.npa.go.jp/publications/statistics/cybersecurity/data/R7/R07_cyber_jousei.pdf
- https://www.npa.go.jp/bureau/cyber/countermeasures/ransom/phobos.html
- https://scan.netsecurity.ne.jp/article/2026/03/17/54851.html
- https://www.tombow-b.jp/4029/
- https://www.bleepingcomputer.com/news/security/police-arrest-lockbit-ransomware-members-release-decryptor-in-global-crackdown/
- https://research.checkpoint.com/2026/the-state-of-ransomware-q1-2026/
Global Discussion
4 comments