Desk live·
ForensicPost
Ransomware/Manufacturing/File 25-1101

Asahi Suspended Manufacturing and Logistics Systems After Qilin Attack

Asahi Group Holdings detected an attack on 29 October 2025 and suspended key systems across manufacturing and logistics. Qilin later claimed responsibility.

Constructed geometry · not a chart of case data
TargetAsahi Group Holdings
ActorQilin
D. Kennedy11 min readConfidence: high2 sources reviewed

Asahi Group Holdings detected a cyberattack on 29 October 2025 and suspended key operational systems across its manufacturing and logistics network. The ransomware operation Qilin subsequently claimed responsibility.

The Third Availability Incident Of The Year At This Scale

Jaguar Land Rover lost five weeks of production at 25-0902. United Natural Foods could not invoice or allocate stock at 25-0606. A brewer suspended manufacturing and distribution.

None of the three is a data breach. All three are cases where the harm was that a physical supply chain stopped, and on the confidentiality-shaped registers this corpus surveys, all three are close to invisible.

Beverage Production Is Closer To JLR Than To A Retailer

Brewing at national scale runs on scheduled batch processes, refrigerated logistics and route planning to thousands of outlets, all sequenced by software. Manual operation is not a degraded mode available at reduced throughput; the throughput is what the software provides.

It is the manual-fallback argument from 25-0902 and 26-0727 in a sector nobody classifies as critical. And the product is perishable, which adds a constraint the automotive case did not have: unsold stock in transit has a clock on it.

Qilin Again

The corpus recorded Qilin as the most prolific operation of 2025 at 25-1108, with reported growth around 420%, and as dominant in the telecom sector at 25-1109.

A claim is a claim, per 26-0425. But the pattern of a single platform appearing across sectors and continents is consistent with the affiliate model: the platform does not choose targets, the affiliates bring whatever access they have, and the largest platform receives the most.

How we reported this

Compiled from public reporting, listed below. Attribution is a claim by the named group. The intrusion route and the duration of the suspension are not established in the material we reviewed. Corrections: corrections@forensicpost.com.

Sources
  1. The biggest cybersecurity and cyberattack stories of 2025BleepingComputer
  2. Top 10 cyber-attacks of 2025Infosecurity Magazine
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary