Desk live·
ForensicPost
Breaches/Method/File 24-0317

Fujitsu Found Malware That Copied Files and Was Not Ransomware

Fujitsu disclosed in March 2024 that malware on a business computer had spread across its internal network in Japan and executed commands to copy files holding personal and customer information. Nothing was encrypted.

Constructed geometry · not a chart of case data
Methods & StandardsThis file records how the desk works, not an incident
JurisdictionJapanTokyothe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetFujitsu
ActorUnattributed
D. Kennedy8 min readConfidence: medium2 sources reviewed

Fujitsu said in March 2024 that it had detected malware across several of its systems. The company reported that the malware was installed on one business computer and spread to others on its internal network in Japan, and that it executed commands to copy files containing personal information and customer business information.

The company described the malware as not being ransomware, and as using techniques that made it hard to detect. It apologised to customers and published the results of its investigation later in the year.

No Encryption Means No Deadline

Ransomware announces itself. It has to: the business model needs the victim to know, quickly, so the clock can start.

Malware that only copies has the opposite requirement. It succeeds by remaining unremarkable, and the organisation finds out through detection rather than through a note. That makes the discovery date a property of the monitoring, not of the intrusion.

What A Technology Supplier Holds

Fujitsu builds and runs systems for other organisations, including governments. Files describing customer business sit on its internal network as a condition of doing the work.

Graded medium: the company disclosed the mechanism in general terms without naming affected customers, publishing a record count, or describing how the first machine was reached.

How we reported this

Compiled from Fujitsu’s notices and public reporting, listed below. No entry route, affected-customer list or record count was published. No actor has been identified. Corrections: corrections@forensicpost.com.

Sources
  1. Fujitsu finds malware on company systems, investigates possible data breachHelp Net Security
  2. Notice regarding results of security incident investigationFujitsu
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary