One day, all of a company's data is suddenly taken hostage. "Pay the ransom and we'll return it," the criminals say. But Japanese companies have a clear answer: "No." Among 15 countries, Japan is the one that pays ransoms the least. That stance is proving, in an unexpected way, to deter cyberattacks.
What Is Ransomware? An Age When Your Data Becomes a "Hostage"
Ransomware is a type of cyberattack in which attackers break into a company's computers, encrypt files, and demand payment to restore them. "Ransom" is exactly what it sounds like, making this a kidnapping of the digital age.
In recent years, rather than merely encrypting data, attackers have made "double extortion," also threatening to publish stolen data, the mainstream approach. Damage is rising year by year, and global ransomware damage is projected to reach about $275 billion a year by 2031 (roughly ¥41 trillion).
Japan: "The Country That Pays Ransoms the Least in the World"
According to a survey of 15 countries by the security firm Proofpoint, Japanese companies have recorded the lowest ransom payment rate among the surveyed countries for three years running.
Japan's payment rate was 33% in 2020 (global average 58%), 20% in 2021 (58%), and 18% in 2022 (64%). While more than half of companies in the United States and the United Kingdom pay ransoms, only about one in five Japanese companies do. Why is the gap so large?
Why Japanese Companies Don't Pay
A Culture of Not Handing Money to Antisocial Forces
Japan has a society-wide principle of "excluding antisocial forces." On top of legislation such as the Anti-Organized-Crime Law, corporate codes of conduct and compliance guidelines explicitly prohibit dealings with organized crime. This thinking applies to ransom payments to cybercriminals as well, and a strong social norm that "money should not be handed to criminal organizations" influences corporate decision-making.
A Backup Culture Born of a Disaster-Prone Nation
Japan is a country where natural disasters such as earthquakes, typhoons, and floods occur frequently. As a result, the habit of routinely backing up data is deeply rooted in many companies. The spirit of "preparedness prevents regret" pays off in ransomware defense too, because if data can be restored from backups, there is no need to pay a ransom.
Cyber Insurance Does Not Cover Ransom Payments
In the West, cyber insurance sometimes covers ransom payments, but Japanese cyber insurance in most cases excludes ransom payments from coverage. As a result, the very option of paying a ransom is economically hard to take. Recently, the West too has been moving to restrict insurance coverage of ransom payments, which suggests Japan's policy was ahead of its time.
The Reality That Paying Doesn't Solve It
Even if a ransom is paid, there is no guarantee data will be fully restored. According to Proofpoint's survey, only 17% of cases in Japan where a ransom was paid saw data restored on the first attempt. Moreover, data shows that 80% of companies that paid were attacked again. Rather than "pay and it's over," the reality is "pay and you're marked as easy prey."
The Effect of Refusing to Pay: Attackers Decide "Japan Isn't Worth It"
Interestingly, Japanese companies' "don't pay" stance has actually produced a drop in ransomware infection rates.
Japan's ransomware infection rate in 2023 was 38%, down a full 30 points from 68% the year before. Given that the global average instead rose 5 points to 69%, Japan's decline stands out.
Yukimi Sohta, chief evangelist at Proofpoint, analyzes that "because Japanese companies did not pay ransoms over many years, a reputation grew among attackers that 'targeting Japan isn't worth it,' which had the effect of curbing financially motivated attacks."
Still No Room for Complacency: New Threats Closing In
But there is no cause for relief. In recent years, the cyber threat environment surrounding Japanese companies has changed rapidly.
AI Has Broken the Language Barrier
Japanese companies were once relatively protected from overseas hackers by the barrier of the Japanese language. If a phishing email's Japanese was unnatural, many employees could tell something was off. But the arrival of generative AI is bringing down that defensive wall. Attackers can now use AI to craft phishing emails in fluent Japanese, and experts warn that the language barrier no longer exists.
A String of Major Incidents
In 2025, leading Japanese companies were hit by ransomware one after another. Asahi Group Holdings, the top beer maker, was attacked in September by the Russia-linked hacker group "Qilin," paralyzing its order and shipping systems. It emerged that about 1.914 million personal records may have leaked, and October beer sales fell just under 10% year on year. The company refused to pay the ransom but needed about five months to normalize its logistics.
Askul, a major office-supplies e-commerce firm, was also attacked, escalating into the shutdown of the e-commerce sites of Muji and Sogo & Seibu.
Reported domestic ransomware cases in the first half of 2025 reached a record 116. In a survey by the security firm Sophos, the number of ransomware victims in Japan over the past year rose 35% year on year.
Structural Challenges
Cybersecurity experts point to structural challenges at Japanese companies. First is a chronic shortage of IT talent; a lack of technical skills is companies' biggest concern (53%). Second is excessive dependence on system integrators. Professor Tetsutaro Uehara of Ritsumeikan University points out that "Japanese companies tend to outsource all of their IT to system integrators," warning that this hinders the accumulation of in-house security expertise. Third is the absence of CIOs (chief information officers); at many Japanese companies the CIO is a mere formality or does not exist at all, so IT is not built into management strategy.
Nationwide Defense Strengthening: The Active Cyber Defense Law
In response to this situation, in May 2025 the Japanese government enacted a landmark law: the Active Cyber Defense Law (formally, the Act on Enhancement of Cyber Response Capabilities).
Until now, Japan's cybersecurity centered on "passive" defense that relied on firewalls and antivirus software, a "siege defense" of holing up in a castle and waiting to be attacked. The new law shifts toward "active defense" that strikes first when it detects signs of an attack, built on four pillars.
First, strengthening public-private cooperation: critical-infrastructure companies are required to report to the government, building a system to share threat information nationwide. Second, use of communication information: under certain conditions, the government can acquire and analyze communication data to analyze cyberattacks. Third, access and neutralization: under defined circumstances, the government is granted authority to access attackers' systems and neutralize attacks. Fourth, organizational structure: the "National Cyber Office (NCO)," newly established in July 2025, serves as the command center overseeing cyber defense.
The law is scheduled for full enforcement during 2026, and Japan's cybersecurity is entering a new stage.
A Global Trend: "Not Paying" Becomes the International Standard
Japan's "don't pay" stance is now becoming the global standard.
In Sophos's 2025 survey, the share of organizations worldwide that paid ransoms fell to 37%, down from 41% the year before. At an international conference gathering representatives of about 50 countries and regions from the U.S., Europe, and Asia, they agreed not to pay ransoms and decided on a policy of urging private companies to follow suit.
Japan's police, too, are showing a presence in international law-enforcement cooperation, taking part in the takedown of the ransomware group LockBit.
What It Takes to Protect a Company
Japanese companies' "don't pay" stance comes with the short-term pain of slower recovery, but in the long term it saps attackers' motivation and has produced a lower infection rate. At the same time, with the evolution of AI technology and increasingly sophisticated attacks, the threats surrounding Japanese companies are growing.
Ahead of the Active Cyber Defense Law's enforcement, companies are called on to have management recognize cyber risk as a management issue, to carry out regular backups and recovery drills, to thoroughly train employees on security, to raise the level of security across the whole supply chain, and to prepare business continuity plans (BCP) for when incidents occur.
How do companies in your country respond to ransomware attacks? Should they pay the ransom, or refuse outright? We'd love to hear your country's thinking and experience.
References
- https://www.proofpoint.com/jp/blog/threat-insight/japan-ransomware-payment-result-2024
- https://www.proofpoint.com/jp/blog/threat-insight/Japans-Ransomware-Payment-Result-2023
- https://xtech.nikkei.com/atcl/nxt/column/18/00001/09289/
- https://www.darkreading.com/cyberattacks-data-breaches/japanese-firms-suffer-long-tail-ransomware-damage
- https://technologymagazine.com/news/ntt-how-japan-leads-in-cybersecurity-amid-rising-threats
- https://www.nippon.com/ja/in-depth/d01147/
- https://www.cas.go.jp/jp/seisaku/cyber_anzen_hosyo_torikumi/index.html
Global Discussion
15 comments