One day, all of a company's data is suddenly taken hostage. "Pay the ransom and we'll return it," the criminals say. But Japanese companies have a clear answer: "No." Among 15 countries, Japan is the one that pays ransoms the least. That stance is proving, in an unexpected way, to deter cyberattacks.

What Is Ransomware? An Age When Your Data Becomes a "Hostage"

Ransomware is a type of cyberattack in which attackers break into a company's computers, encrypt files, and demand payment to restore them. "Ransom" is exactly what it sounds like, making this a kidnapping of the digital age.

In recent years, rather than merely encrypting data, attackers have made "double extortion," also threatening to publish stolen data, the mainstream approach. Damage is rising year by year, and global ransomware damage is projected to reach about $275 billion a year by 2031 (roughly ¥41 trillion).

Japan: "The Country That Pays Ransoms the Least in the World"

According to a survey of 15 countries by the security firm Proofpoint, Japanese companies have recorded the lowest ransom payment rate among the surveyed countries for three years running.

Japan's payment rate was 33% in 2020 (global average 58%), 20% in 2021 (58%), and 18% in 2022 (64%). While more than half of companies in the United States and the United Kingdom pay ransoms, only about one in five Japanese companies do. Why is the gap so large?

Why Japanese Companies Don't Pay

A Culture of Not Handing Money to Antisocial Forces

Japan has a society-wide principle of "excluding antisocial forces." On top of legislation such as the Anti-Organized-Crime Law, corporate codes of conduct and compliance guidelines explicitly prohibit dealings with organized crime. This thinking applies to ransom payments to cybercriminals as well, and a strong social norm that "money should not be handed to criminal organizations" influences corporate decision-making.

A Backup Culture Born of a Disaster-Prone Nation

Japan is a country where natural disasters such as earthquakes, typhoons, and floods occur frequently. As a result, the habit of routinely backing up data is deeply rooted in many companies. The spirit of "preparedness prevents regret" pays off in ransomware defense too, because if data can be restored from backups, there is no need to pay a ransom.

Cyber Insurance Does Not Cover Ransom Payments

In the West, cyber insurance sometimes covers ransom payments, but Japanese cyber insurance in most cases excludes ransom payments from coverage. As a result, the very option of paying a ransom is economically hard to take. Recently, the West too has been moving to restrict insurance coverage of ransom payments, which suggests Japan's policy was ahead of its time.

The Reality That Paying Doesn't Solve It

Even if a ransom is paid, there is no guarantee data will be fully restored. According to Proofpoint's survey, only 17% of cases in Japan where a ransom was paid saw data restored on the first attempt. Moreover, data shows that 80% of companies that paid were attacked again. Rather than "pay and it's over," the reality is "pay and you're marked as easy prey."

The Effect of Refusing to Pay: Attackers Decide "Japan Isn't Worth It"

Japanese companies' "don't pay" stance has actually produced a drop in ransomware infection rates.

Japan's ransomware infection rate in 2023 was 38%, down a full 30 points from 68% the year before. Given that the global average instead rose 5 points to 69%, Japan's decline stands out.

Yukimi Sohta, chief evangelist at Proofpoint, analyzes that "because Japanese companies did not pay ransoms over many years, a reputation grew among attackers that 'targeting Japan isn't worth it,' which had the effect of curbing financially motivated attacks."

Still No Room for Complacency: New Threats Closing In

But there is no cause for relief. In recent years, the cyber threat environment surrounding Japanese companies has changed rapidly.

AI Has Broken the Language Barrier

Japanese companies were once relatively protected from overseas hackers by the barrier of the Japanese language. If a phishing email's Japanese was unnatural, many employees could tell something was off. But the arrival of generative AI is bringing down that defensive wall. Attackers can now use AI to craft phishing emails in fluent Japanese, and experts warn that the language barrier no longer exists.

A String of Major Incidents

In 2025, leading Japanese companies were hit by ransomware one after another. Asahi Group Holdings, the top beer maker, was attacked on September 29 by the Russia-linked hacker group "Qilin," paralyzing its order and shipping systems. The company disclosed that about 1.91 million personal records may have leaked, and October beer sales fell just under 10% year on year. Asahi never made contact with the attackers and paid no ransom.

Update: in its final investigation results on February 18, 2026, Asahi said the leak actually confirmed covered about 115,000 records belonging to business partners and employees. Shipping operations were not fully normalized until April 2026, and in June the company cut its full-year forecast for the December 2025 period, citing the system failure in its Japanese business. The intruders had entered about ten days before the outage through a network device at a group site, then seized administrator privileges by exploiting a password weakness in the data center. Asahi's remediation plan centers on eliminating VPNs and moving to zero trust.

Askul, a major office-supplies e-commerce firm, was also attacked, escalating into the shutdown of the e-commerce sites of Muji and Sogo & Seibu.

Reported domestic ransomware cases in the first half of 2025 reached a record 116. In a survey by the security firm Sophos, the number of ransomware victims in Japan over the past year rose 35% year on year.

Structural Challenges

Cybersecurity experts point to structural challenges at Japanese companies. First is a chronic shortage of IT talent; a lack of technical skills is companies' biggest concern (53%). Second is excessive dependence on system integrators. Professor Tetsutaro Uehara of Ritsumeikan University points out that "Japanese companies tend to outsource all of their IT to system integrators," warning that this hinders the accumulation of in-house security expertise. Third is the absence of CIOs (chief information officers); at many Japanese companies the CIO is a mere formality or does not exist at all, so IT is not built into management strategy.

Nationwide Defense Strengthening: The Active Cyber Defense Law

In response, on May 16, 2025 the Japanese government enacted the "Active Cyber Defense Law." Its formal title is the Act on Prevention of Damage from Unauthorized Acts Against Critical Computers; it is commonly called the Cyber Response Capability Enhancement Act, and was promulgated on May 23.

Until now, Japan's cybersecurity centered on "passive" defense that relied on firewalls and antivirus software, a "siege defense" of holing up in a castle and waiting to be attacked. The new law shifts toward "active defense" that strikes first when it detects signs of an attack, built on four pillars.

First, strengthening public-private cooperation: critical-infrastructure companies are required to report to the government, building a system to share threat information nationwide. Second, use of communication information: under certain conditions, the government can acquire and analyze communication data to analyze cyberattacks. Third, access and neutralization: under defined circumstances, the government is granted authority to access attackers' systems and neutralize attacks. Fourth, organizational structure: the "National Cyber Office (NCO)," newly established in July 2025, serves as the command center overseeing cyber defense.

Enforcement has been phased in since April 2026, and the core provisions, communications analysis and access-and-neutralization, come into play the same year. The second and third pillars require prior approval from an independent commission as a check on the powers involved.

A Global Trend: "Not Paying" Becomes the International Standard

Japan's "don't pay" stance is now becoming the global standard.

In Sophos's 2025 survey, the share of organizations worldwide that paid ransoms fell to 37%, down from 41% the year before. At an international conference gathering representatives of about 50 countries and regions from the U.S., Europe, and Asia, they agreed not to pay ransoms and decided on a policy of urging private companies to follow suit.

Japan's police, too, are showing a presence in international law-enforcement cooperation, taking part in the takedown of the ransomware group LockBit.

What It Takes to Protect a Company

Refusing to pay protects a company only against attackers who are in it for the money. As Asahi's five months showed, the cost borne by the side that refuses does not disappear.

What companies need is for management to treat cyber risk as a management issue. From there: regular backups and recovery drills, employee training, security raised across the whole supply chain, and a business continuity plan for the day an incident lands. Only with the capacity to recover does "we don't pay" become a real option.

How do companies in your country respond to ransomware attacks? Should they pay the ransom, or refuse outright? We'd love to hear your country's thinking and experience.

References