Desk live·
ForensicPost
Ransomware/Retail/File 25-1002

A Retailer That Was Never Attacked Stopped Selling

Muji halted online sales after the ransomware attack on its delivery partner Askul. Its own systems were fine.

Constructed geometry · not a chart of case data
JurisdictionJapanTokyothe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetMuji
ActorRansomHouse
S. Rosler11 min readConfidence: high2 sources reviewed

The Japanese retailer Muji halted online sales in October 2025 following the ransomware attack on its logistics partner Askul, recorded at 25-1011. Muji itself was not compromised.

The Cleanest Downstream File In The Corpus

This database is full of third-party incidents where an organisation’s data was lost by a supplier: Marquis at 25-0814, Chain IQ at 25-0613, the back-office administrator at 25-0801.

This is the operational version. No Muji data was involved. No Muji system was touched. The company could not trade because the organisation that moves its goods could not move them.

It is what UNFI at 25-0606 looked like from the retailer’s side, and what JLR at 25-0928 looked like to the suppliers the UK government guaranteed lending for.

Nothing Obliges Anyone To Record It

Askul will report its data breach. Muji has no breach to report — no personal data was involved, so no notification arises anywhere.

The corpus filed at 25-1223 that availability harm outside regulated sectors falls outside every 2025 reform, and at 25-0708 that insurance claims are the only place such harm is systematically measured. A retailer’s lost trading days from a supplier’s incident appear in neither.

And Logistics Concentration Made It Possible

This desk filed at 25-1114 that logistics sits between every other sector and has no perimeter, because the sector is the interfaces.

A retailer that outsources fulfilment to a specialist gets better rates and better service. It also acquires a single point of failure it does not operate, cannot inspect, and — as here — cannot route around within a trading day.

How we reported this

Compiled from public reporting, listed below. The duration of the sales suspension and the revenue effect are not established. Corrections: corrections@forensicpost.com.

Sources
  1. Retail giant Muji halts online sales after ransomware attack on supplierBleepingComputer
  2. Muji’s minimalist vibe wrecked amid supply chain attackThe Register
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary