IDC Frontier says customers affected by a ransomware attack on IDCF Cloud should rebuild workloads in separate environments using backups they hold themselves, after the provider concluded that data in four zones of East Japan Region 1 will be difficult to retrieve or restore.
The outage began at about 3:40 a.m. Japan Standard Time on October 7, 2026. IDC Frontier says 495 companies and local governments are affected. On October 8, the company identified the impacted zones as tesla, henry, pascal and joule, where virtual servers are stopped and cannot be restarted.
Virtual servers in four East Japan Region 1 zones remain unavailable, and IDC Frontier says affected customers should rebuild from customer-held backups in separate environments.
Four zones remain unavailable
IDC Frontier confirmed on October 7 that the disruption was caused by a third-party ransomware attack. It disconnected East Japan Region 1 from the network and stopped systems to limit further damage while investigating the intrusion route and scope of the compromise.
The October 8 update materially changed the recovery picture. IDC Frontier said customer data stored in the four affected zones is expected to be difficult to extract or restore. Its current assessment is that restoration can be performed only from backup data retained by customers outside the affected environment.
The provider is therefore advising affected customers to prepare a separate environment and rebuild there. That makes the incident more than a temporary availability problem: recovery now depends on whether each customer has a usable backup that is independent of the damaged cloud environment.
Other regions face precautionary controls
IDC Frontier said it had not confirmed unauthorized access in the radian and newton zones of East Japan Region 1, East Japan Regions 2 and 3, or West Japan Region 1 as of its October 8 report. However, the company has asked customers in those environments to create their own backups.
Customer access to the IDCF Cloud management console was also suspended while the provider checked the safety of other regions. With the console unavailable, IDC Frontier said it was carrying out some virtual-server start and stop operations on behalf of customers when requested.
IDCF Cloud TypeS, formerly White Cloud ASPIRE, and IDCF Private Cloud are outside the scope of the incident, according to the company.
No recovery timetable has been announced
IDC Frontier has not publicly disclosed the initial intrusion route, named a ransomware group or confirmed whether customer data was exfiltrated. The company says it is continuing the technical investigation with an external security specialist.
On October 9, IDC Frontier said it had established an emergency response headquarters on the morning of October 7 and was working with parent company SoftBank on customer support, investigation and recovery planning. It also said it was reporting and consulting with regulators and police. The update did not provide a timetable for restoring the affected four zones.
What infrastructure teams should do now
For affected operators, the immediate task is to identify which workloads were hosted in the four named zones, verify the integrity and age of backups held outside the affected environment, and prepare a clean target environment for restoration. Customers in other IDCF regions should also follow the provider’s request to take backups while the broader security review continues.
The incident is a direct test of cloud recovery design. A backup that depends on the same provider, management plane or compromised region may not be sufficient when both compute and control access are disrupted. Infrastructure teams should treat provider snapshots and independently held recovery copies as separate layers, and verify that critical services can be rebuilt without access to the original region.







