№ 046 / Blog
Structural Analysis Notes · 2026.10.08

The Day a Cloud Vanished — Five Lessons from the IDCF Incident

The provider told customers that snapshots could not be restored and that its other regions were not recommended for now. Keep your copy on another machine, in another place, under another authority

What Happened

In the early hours of 7 October 2026, a third party broke into East Japan Region 1 of IDCF Cloud, run by SoftBank subsidiary IDC Frontier, and ransomware brought the platform down. In its seventh notice to customers, the provider wrote: recovery of the data and virtual machines in the affected environment is extremely difficult; restoring from snapshots is also difficult; rebuilding in its other regions is not recommended until their safety is confirmed; data can be restored only from backups the customers hold themselves.

On top of this cloud sat telephone services, e-commerce inventory systems, the management consoles of security products, and a speech-recognition app. The outage ran down a three-tier chain — user, SaaS, platform — all the way to each end user. The entry route, the exact extent of the damage, and the truth of the attacker's claims were unconfirmed when this was written.

Anyone who wants the details can have an AI look them up. What stays here is the lessons.

Five Lessons

  1. A snapshot is not a backup. A copy that sits on the same platform as the original disappears with the platform. Keep your copy on another machine, in another place, under another authority.
  2. Separate regions are one failure domain if the management plane is one. The provider itself said its other regions were not recommended for now. Geographic separation and separation of authority are different things.
  3. The higher you sit in the chain of outsourcing, the less you have read the contract. Cloud contracts have always made the customer responsible for keeping a copy of the data. The company that put its service on the cloud, and the users of that service, each assumed the tier below held a copy.
  4. The number of defenders decides what can be defended. A platform that advertises 24-hour monitoring is a signboard if nobody is looking. On a machine of your own, one person holds the management plane, and the failure domain closes at that one machine.
  5. Be able to do it in-house. Your own people, on your own machine, have taken a copy, restored it, and rebuilt a server. The moment you tell a contractor "take care of it," you are back in the three-tier chain. The procedures are in the server series; the first two lessons were added to the 3-2-1 rule in Chapter 10.

Related

References

  1. ITmedia NEWS, "Unauthorized access to IDCF Cloud; outage in East Japan Region 1" (7 October 2026) — https://www.itmedia.co.jp/news/article/2610/07/2000002087/
  2. IDC Frontier, "IDCF Cloud incident notice (7th report)" (October 2026, notice to customers)
  3. List of affected services (Security Measures Lab, 7 October 2026) — https://rocket-boys.co.jp/security-measures-lab/idcf-cloud-outage-affected-services-2026/