Ryohin Keikaku (Muji)

Ryohin Keikaku (Muji)

Ryohin Keikaku, the operator of Muji, halted its domestic online shopping service on October 19 due to a ransomware attack on its delivery partner, Askul. The attack disrupted order processing and shipping operations for Muji’s official online store, with no confirmed resumption date. Askul is investigating potential leaks of personal or customer data, though the scope remains undetermined. The incident follows a broader wave of cyberattacks in Japan, including a separate ongoing attack on Asahi Breweries since late September, also linked to the Qilin ransomware group (allegedly Russian-based). Muji’s parent company saw a 2.5% share drop, while Askul’s shares fell over 5%. The attack forced manual order processing, financial delays (e.g., Asahi postponed earnings reports), and operational disruptions, though Muji’s physical stores and Asahi’s production plants remained partially functional. The perpetrators’ demands were not disclosed, but the attack’s financial, reputational, and operational impact was immediate and significant.

Source: https://www.straitstimes.com/asia/east-asia/japans-muji-hit-by-ransomware-attack-on-delivery-partner

TPRM report: https://www.rankiteo.com/company/ryohin-keikaku

"id": "ryo0792107102025",
"linkid": "ryohin-keikaku",
"type": "Ransomware",
"date": "9/2025",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization’s existence"
{'affected_entities': [{'industry': 'retail (home goods, apparel)',
                        'location': 'Japan',
                        'name': 'Ryohin Keikaku (Muji)',
                        'type': 'retailer'},
                       {'industry': 'e-commerce logistics',
                        'location': 'Japan',
                        'name': 'Askul',
                        'type': 'logistics/online shopping delivery partner'},
                       {'industry': 'beverage (alcohol)',
                        'location': 'Japan',
                        'name': 'Asahi Group Holdings',
                        'type': 'brewing company'}],
 'data_breach': {'personally_identifiable_information': 'potential (under '
                                                        'investigation)',
                 'type_of_data_compromised': 'potential (personal information '
                                             'or customer data, under '
                                             'investigation)'},
 'date_detected': '2023-10-19T21:00:00+09:00',
 'date_publicly_disclosed': '2023-10-20',
 'description': 'Ryohin Keikaku (Muji) suspended its domestic online shopping '
                'service due to a ransomware attack on its delivery partner, '
                'Askul. The attack began affecting systems on October 19, '
                '2023, with no confirmed resumption date. Askul is '
                'investigating potential compromise of personal or customer '
                'data. Separately, Japanese brewing giant Asahi has been '
                'dealing with an ongoing cyberattack since September 29, 2023, '
                'attributed to the Russian-based hacker group Qilin.',
 'impact': {'brand_reputation_impact': ['share price drop: Ryohin Keikaku '
                                        '(-2.5% to -6%), Askul (-5%)'],
            'data_compromised': 'potential (under investigation; personal or '
                                'customer data may be affected)',
            'downtime': {'Asahi': {'end': None,
                                   'start': '2023-09-29',
                                   'status': 'ongoing (partial manual '
                                             'processing)'},
                         'Muji/Askul': {'end': None,
                                        'start': '2023-10-19T21:00:00+09:00',
                                        'status': 'ongoing (resumption date '
                                                  'undetermined)'}},
            'identity_theft_risk': 'potential (under investigation)',
            'operational_impact': ['suspended order processing',
                                   'halted shipping operations (Muji/Askul)',
                                   'manual order processing (Asahi)',
                                   'delayed financial results release (Asahi)'],
            'systems_affected': ['order processing systems',
                                 'shipping operations']},
 'investigation_status': 'ongoing (Askul investigating scope of impact, '
                         'including data compromise)',
 'ransomware': {'data_encryption': 'likely (system failure caused by '
                                   'ransomware)'},
 'references': [{'source': 'The Straits Times'},
                {'source': 'AFP (Agence France-Presse)'}],
 'response': {'communication_strategy': ['public statements by Muji (Oct 20) '
                                         'and Asahi (Oct 20)'],
              'containment_measures': ['suspension of order processing and '
                                       'shipping operations'],
              'incident_response_plan_activated': 'yes (collaboration with '
                                                  'Askul for restoration)',
              'recovery_measures': ['manual order processing (Asahi)',
                                    'gradual resumption of shipments (Asahi)']},
 'stakeholder_advisories': ['public statements by Muji and Asahi'],
 'threat_actor': 'Qilin (suspected, Russian-based hacker group)',
 'title': "Ransomware Attack on Muji's Online Shopping Delivery Partner Askul",
 'type': ['ransomware', 'cyberattack']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.