Askul’s Cyber Crisis: How a Ransomware Attack Shook a Major Retailer

In late 2025, one of Japan’s most well-known office supply retailers quietly found itself dealing with a serious cyberattack. Askul Corporation, a company that many businesses and households rely on for everyday goods, confirmed that a ransomware incident had led to the theft of a large amount of customer and partner data.

By the time the company went public with the full details in mid-December, it became clear that this was not a minor incident. Roughly 740,000 sets of personal and business records had been accessed by attackers, making it one of the largest retail-related data breaches in Japan that year.


Who Askul Is and Why This Matters

Askul is a major name in Japan’s retail and logistics space. It supplies office materials, household products, and business services through several platforms, including its core Askul service for corporate customers and Lohaco for individual shoppers. Many companies depend on Askul’s logistics network to keep daily operations running.

Because of that role, when Askul’s systems were disrupted, the impact was felt far beyond the company itself.


How the Attack Came to Light

Askul first noticed something was wrong in October 2025, when unusual activity appeared inside its internal systems. Engineers soon confirmed that ransomware had entered the environment, affecting core systems tied to order processing and warehouse operations.

To prevent the situation from getting worse, the company acted quickly. Infected systems were taken offline, and online ordering was suspended across all major platforms. Distribution centers relying on those systems also had to pause operations.

At this stage, Askul focused on containment and investigation. There was no immediate confirmation that customer data had been stolen, only that systems had been compromised.


The Leak Becomes Public

Later in October, a ransomware group calling itself RansomHouse publicly claimed responsibility. The group posted Askul’s name on its leak site and claimed it had stolen more than a terabyte of internal data.

Over the following weeks, the attackers released samples of stolen information online, increasing pressure on the company. By early December, it was clear that the breach involved real customer and business records.

Askul officially confirmed the scale of the data exposure on December 13–14, 2025, marking the first time specific numbers were shared publicly.


What Data Was Exposed

According to Askul’s disclosure, the compromised data included approximately:

  • 590,000 corporate customer records from its office supplies business
  • 130,000 individual customer records from its consumer platform
  • 20,000 employee-related records

The exposed information included names, contact details, inquiry records, and business-related data stored on internal servers.

Askul stressed that credit card information was not affected, which helped reduce immediate financial risk for customers. However, the company acknowledged that personal and business information had been accessed and copied.


Did Askul Pay the Ransom?

Askul has clearly stated that no ransom payment was made.

Instead, the company chose to focus on system recovery, internal investigation, and regulatory reporting. All affected parties are being notified directly, and the breach has been formally reported to Japan’s Personal Information Protection Commission, as required under national data protection laws.


Operational Fallout and Slow Recovery

The cyberattack didn’t just expose data—it disrupted real-world operations.

Because Askul’s warehouse and logistics systems were affected, shipments across Japan were delayed. Other retailers that rely on Askul’s distribution network were also impacted, forcing temporary suspensions of online orders in some cases.

Recovery happened in stages. At first, only limited manual orders were accepted for critical customers, such as healthcare facilities. Over time, online ordering resumed for corporate customers, followed by broader service restoration. Full operational recovery was planned for mid-December.


Law Enforcement and Investigation

Japanese authorities are involved in the investigation, and Askul has stated that it is cooperating fully. As part of the inquiry, authorities conducted on-site investigative actions in early December to independently review systems and incident response measures.

Internally, Askul rebuilt affected systems from clean environments. Devices suspected of being compromised were either wiped or physically replaced, rather than reused. The company has said it sees no signs of ongoing attacker presence.


How Attacks Like This Are Detected

Ransomware groups like RansomHouse usually leave behind warning signs long before files are encrypted.

Common indicators include:

  • Unexpected system slowdowns or crashes
  • Large volumes of data being accessed or compressed
  • Unusual outbound network traffic, especially after hours
  • Security tools being disabled without explanation
  • Backup systems or shadow copies suddenly disappearing

In this case, early system anomalies helped Askul detect the issue before it spread further, but data theft had already occurred.


What Organizations Can Learn From This

The Askul incident shows that ransomware is no longer just about locked files. Data theft now plays a central role, increasing pressure on victims even if systems can be restored.

Key lessons include:

  • Monitoring for unusual access to core business systems
  • Limiting how much data any single system or account can access
  • Treating logistics and warehouse platforms as high-risk assets
  • Responding fast, even before the full scope is known

It also highlights the importance of transparency. By publicly disclosing details and notifying affected parties, Askul took steps to rebuild trust, even under difficult circumstances.


Final Takeaway

Askul was hit by a ransomware attack that stole data and disrupted operations. The company did not pay the attackers, shut down systems to stop the spread, and later confirmed that around 740,000 records were affected. While payment data remained safe, personal and business information was exposed.

The incident serves as a reminder that even well-established companies can be vulnerable—and that the real damage from ransomware often continues long after systems come back online.

Aegiron

Backed by 11+ years in cybersecurity and incident response, we decode the latest threats shaping today’s digital battlefield. This blog cuts through the noise with clear insights on vulnerabilities, emerging exploits, and the cyber news defenders can’t afford to miss.