Site navigation

Asahi Weighs Major Cybersecurity Overhaul

Graham Turner

,

Asahi cyberattack
The Japanese brewing giant is now weighing a dedicated cybersecurity unit and a shift to a zero-trust security model.

Asahi Group Holdings is preparing a significant overhaul of its cybersecurity strategy following a ransomware attack that continues to disrupt operations and financial reporting months after the initial breach.

The Japanese brewing giant confirmed it is considering the creation of a dedicated cybersecurity unit, elevating information security to a top management priority. Chief executive Atsushi Katsuki said the decision follows a ransomware attack in late September that exposed personal data and forced widespread operational disruption across the group’s Japan-based systems.

The cyberattack was detected when a system disruption was identified within Asahi’s network. Subsequent investigations confirmed that ransomware had encrypted files across multiple live servers, as well as some employee PCs connected to the network. By approximately 11:00am the same day, Asahi disconnected its network and isolated its data centre in an effort to contain the damage.

According to the company, the attacker gained unauthorised access through network equipment at a group facility, deploying ransomware simultaneously across several systems.

While the impact was limited to systems managed in Japan, the disruption was extensive, freezing core business operations and forcing the company to suspend automated order processing and shipping. Asahi was required to switch to manual handling of orders and deliveries, delaying shipments including year-end gift sets, a key seasonal product in the Japanese beverage market.

The attack was claimed by the ransomware group Qilin. Asahi has said operational disruptions may continue until at least February 2026, with Katsuki describing the current recovery as extending into a “reconstruction phase” after February. “We are committed not just to restoring our shipments to past levels but to exceeding them,” he added.

As part of its recovery plan, Asahi Group Holdings has scrapped the use of virtual private networks and is adopting a stricter zero-trust security model, which assumes no user or device inside the network can be automatically trusted. Katsuki said information security must be treated as a core management issue, adding: “Information security is a management issue that should be given the highest priority.”

The first financial consequences of the attack are now emerging. Asahi reported a 20% year-on-year drop in alcohol sales in Japan in November 2025, reflecting the ongoing system disruption. The company has also postponed the disclosure of detailed sales performance data, refraining from releasing monthly sales figures by category and brand for a third consecutive month, citing difficulties in accurately compiling the data while systems remain affected.

Financial reporting has also been delayed. Asahi expects its annual earnings disclosure to be pushed back by more than 50 days. While partial third-quarter figures were released in November, Katsuki declined to provide a revised timeline for the full results. Prior to the cyberattack, the company had forecast operating profit for the year ending in December to fall 5.2% to ¥255 billion, on sales of ¥2.95 trillion.

Alongside operational recovery, Asahi has been conducting a forensic investigation with external cybersecurity experts.

In a statement issued on November 27, 2025, the company confirmed that personal data had been exposed as a result of the attack. This includes information relating to approximately 1.525 million individuals who contacted customer service centres of Asahi Breweries, Asahi Soft Drinks and Asahi Group Foods; 114,000 external contacts associated with congratulatory or condolence telegrams; 107,000 employees and retirees; and 168,000 family members of employees and retirees. Asahi said no credit card information was included.

The company added that, as of that date, there was no confirmation that server-based personal data had been published online. On November 26, Asahi submitted its final report to Japan’s Personal Information Protection Commission and said affected individuals would be notified in due course. A dedicated inquiry hotline has been established to handle questions related to the data exposure.


Recommended reading


System restoration efforts have taken roughly two months so far and have included ransomware containment, integrity checks and the introduction of enhanced security measures.

Asahi said systems and devices confirmed to be secure are being restored in phases, with ongoing monitoring in place to prevent recurrence. Preventive steps outlined by the company include redesigned network controls, stricter connection restrictions, improved threat detection, updated backup strategies, revised business continuity plans, and expanded employee training and external audits.

Despite the scale of the disruption, Katsuki said the breach does not threaten Asahi’s long-term foundation and expressed confidence that lost market share can be recovered. He expects most systems to be restored by February, with full competitive positioning returning from March.

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data