Asahi Group Holdings

Asahi Group Holdings

Asahi Group Holdings, the Japanese beverage giant and producer of **Asahi Super Dry**, suffered a **ransomware attack** in late September 2024, disrupting its operations. The attack forced the company to **delay the release of its full-year financial results** (fiscal year ending December 2025) due to ongoing system recovery efforts. While **shipments are gradually resuming**, the incident caused **operational disruptions**, including potential delays in production and distribution. The attack was claimed by the **Qilin hacker group**, allegedly based in Russia, though Asahi has not confirmed the perpetrator’s identity or ransom demands. The incident highlights the growing threat of ransomware against high-profile corporations, with Asahi joining other global victims like **Jaguar Land Rover** (factory halts) and **Muji** (online service shutdowns). The financial and reputational impact remains significant, as the company works to restore systems while managing public trust and supply chain stability.

Source: https://www.digitaljournal.com/world/japan-beer-giant-asahi-delays-earnings-due-to-cyberattack/article

Asahi Group Holdings cybersecurity rating report: https://www.rankiteo.com/company/asahigroup-holdings

"id": "ASA5662456112725",
"linkid": "asahigroup-holdings",
"type": "Ransomware",
"date": "9/2024",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization’s existence"
{'affected_entities': [{'industry': 'beverage (alcohol/beer)',
                        'location': 'Japan',
                        'name': 'Asahi Group Holdings',
                        'size': 'large enterprise',
                        'type': 'public company'}],
 'customer_advisories': ['apology for inconvenience',
                         'request for understanding during recovery'],
 'data_breach': {'data_encryption': True},
 'date_detected': '2025-09-29',
 'date_publicly_disclosed': '2025-09-29',
 'description': 'Japanese beer giant Asahi Group Holdings, maker of Asahi '
                'Super Dry, was hit by a ransomware attack in late September '
                '2025. The attack disrupted operations, delayed the release of '
                'full-year financial results, and caused partial shipment '
                'halts. The company is working to restore systems, with '
                'shipments resuming in stages. The hacker group Qilin, '
                'believed to be based in Russia, is suspected to be '
                'responsible.',
 'impact': {'brand_reputation_impact': 'potential negative impact due to '
                                       'operational disruption',
            'downtime': 'ongoing (as of disclosure, partial recovery in '
                        'progress)',
            'operational_impact': 'delayed financial results, disrupted '
                                  'product shipments (resuming in stages)',
            'systems_affected': ['financial reporting systems',
                                 'supply chain/logistics systems']},
 'initial_access_broker': {'high_value_targets': ['financial systems',
                                                  'supply chain systems']},
 'investigation_status': 'ongoing',
 'motivation': 'financial (ransomware)',
 'ransomware': {'data_encryption': True},
 'references': [{'source': 'AFP (Agence France-Presse)'},
                {'source': 'Asahi Group Holdings public statement (September '
                           '29, 2025)'},
                {'source': "Japanese media reports on Qilin's claim of "
                           'responsibility'}],
 'response': {'communication_strategy': ['public statement by CEO Atsushi '
                                         'Katsuki',
                                         'apology for inconvenience'],
              'containment_measures': ['system isolation',
                                       'restoration efforts'],
              'incident_response_plan_activated': True,
              'recovery_measures': ['phased resumption of product shipments'],
              'remediation_measures': ['system recovery in progress']},
 'stakeholder_advisories': ['delay in financial results announcement',
                            'phased resumption of shipments'],
 'threat_actor': 'Qilin (suspected, Russia-based)',
 'title': 'Ransomware Attack on Asahi Group Holdings',
 'type': 'ransomware'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.