The Japanese retailer Muji halted online sales in October 2025 following the ransomware attack on its logistics partner Askul, recorded at 25-1011. Muji itself was not compromised.
The Cleanest Downstream File In The Corpus
This database is full of third-party incidents where an organisation’s data was lost by a supplier: Marquis at 25-0814, Chain IQ at 25-0613, the back-office administrator at 25-0801.
This is the operational version. No Muji data was involved. No Muji system was touched. The company could not trade because the organisation that moves its goods could not move them.
It is what UNFI at 25-0606 looked like from the retailer’s side, and what JLR at 25-0928 looked like to the suppliers the UK government guaranteed lending for.
Nothing Obliges Anyone To Record It
Askul will report its data breach. Muji has no breach to report — no personal data was involved, so no notification arises anywhere.
The corpus filed at 25-1223 that availability harm outside regulated sectors falls outside every 2025 reform, and at 25-0708 that insurance claims are the only place such harm is systematically measured. A retailer’s lost trading days from a supplier’s incident appear in neither.
And Logistics Concentration Made It Possible
This desk filed at 25-1114 that logistics sits between every other sector and has no perimeter, because the sector is the interfaces.
A retailer that outsources fulfilment to a specialist gets better rates and better service. It also acquires a single point of failure it does not operate, cannot inspect, and — as here — cannot route around within a trading day.
Compiled from public reporting, listed below. The duration of the sales suspension and the revenue effect are not established. Corrections: corrections@forensicpost.com.