Desk live·
ForensicPost
Ransomware/Logistics/File 25-1011

Seven Hundred and Forty Thousand Records, and the Shops Shut

Askul detected a ransomware attack on 19 October 2025. Around 740,000 sets of customer, corporate and employee data were leaked, and its logistics operations stopped.

Constructed geometry · not a chart of case data
TargetAskul Corporation
ActorRansomHouse
D. Kennedy12 min readConfidence: high3 sources reviewed

The Japanese office-supplies and logistics company Askul detected a ransomware attack on 19 October 2025, halting online orders and shipments. RansomHouse claimed responsibility on 30 October. The company later confirmed the leakage of approximately 740,000 sets of data concerning individual customers, corporate clients and employees.

Both Halves At Once

This corpus separates its incidents by what was lost. Availability files — JLR at 25-0902, UNFI at 25-0606, Asahi at 25-1101 — record operations stopping with no measured data loss. Confidentiality files record data taken with operations intact.

Askul is both, with figures for each. Seven hundred and forty thousand records and a logistics network that stopped moving. It is one of very few files here where the corpus can see the full cost of a single incident.

The Record Set Spans Three Populations

Individual customers, corporate clients and employees, counted together. This desk filed at 25-0704 that workforce exposure is systematically under-recorded because no register covers it, and at 25-0613 that a procurement platform accumulated nineteen organisations’ staff directories.

Askul reported all three in one figure, which is more honest than most disclosures in this database and makes the number harder to interpret. Seven hundred and forty thousand "sets" is not seven hundred and forty thousand people — the reachable-versus-taken-versus-published problem at 25-0717.

And Japan’s Incident Record Is Thin

The corpus documented at 25-0502 the four filters that decide which incidents become public, and at 25-1225 that this database is overwhelmingly American and British.

Askul appears here with a date, a claimed actor, a record count and an operational account — better documented than most non-Western files in this corpus. That is not typical, and the corpus should not treat it as evidence that Japanese incidents are generally this visible.

How we reported this

Compiled from public reporting and company statements, listed below. Attribution is a group claim. The 740,000 figure counts data sets across three populations as reported. Corrections: corrections@forensicpost.com.

Sources
  1. Askul says 740,000 sets of data breached in cyberattackThe Japan Times
  2. Japanese retailer Askul halts online orders, shipments after ransomware attackThe Record
  3. Askul cyberattack: logistics operations begin to resumeThe Cyber Express
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary