Japanese retailer Muji has been hit by a major cybersecurity incident, forcing it to shut down its online store after a ransomware attack on its key delivery partner, Askul Corporation. The incident has once again highlighted how vulnerable supply chains are to modern digital threats.

The chain reaction of a ransomware attack
On Sunday evening (Japan time), Muji announced that the cyberattack on Askul caused disruptions to all retail services — from browsing online stores to accessing order history via the Muji App. For several hours, even viewing online content was disrupted, causing disruption to customers.
By Monday afternoon, the company said some services had been restored, but online shopping and subscription services were still experiencing issues. Muji is investigating which parcels and shipments were affected and will notify customers individually via email.
See also: ClickFix: TikTok videos distribute info-stealer malware
A company with a global footprint
Muji has over 1,000 stores in Japan, China, Europe, Australia and North America. With annual revenues exceeding $4 billion and a staff of over 24,500 employees, the company is one of the most powerful players in the retail of designer home goods and clothing.
The cyberattack, however, is a reminder that even organizations with robust infrastructures are not immune when their partners are targeted.
Askul: The "weak link" in the supply chain
Askul Corporation, owned by Yahoo! Japan Corporation, is one of the largest e-commerce and logistics providers in Japan, serving both businesses and individuals. According to an official statement, its website has been infected with ransomware, which has led to a complete suspension of orders and shipping operations.
The company says it is investigating the scope of the breach, as well as the potential for customer data to be compromised. At the same time, all product return, receipt and catalog services have been suspended, while the phone and online customer service center remain down.

The impact is limited to Japan
Fortunately for Muji, Askul is solely responsible for managing sales within Japan. As such, physical and online stores Muji's (such as in Europe and the Americas) are operating normally. However, the damage to the local market is significant, as the company relies heavily on its Japanese presence for the majority of its revenue.
See also: US nuclear weapons plant hacked via SharePoint
No liability – for now
So far, no known ransomware group has claimed responsibility for the attack via the well-known dark web “extortion portals.” However, experts believe that this is a targeted attack on critical supply infrastructure, with the aim of extorting money through the threat of data leakage.
New surge in cyberattacks in Japan
The incident comes shortly after the attack on beer giant Asahi, which forced it to halt production and delay product releases, was claimed by the ransomware Qilin, which had stolen corporate data.
The two attacks, within a short period of time, mark a worrying escalation of cybercriminal activities against large Japanese companies, confirming that supply chains are now the new "target of choice" for hackers.
See also: China accuses US of cyberattack on National Time Center
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The Big Picture: The Security of the Logistics Era
The Muji and Askul incident is a prime example of how an attack on one partner can have ripple effects throughout the entire business chain. Reliance on third parties for logistics, warehousing and deliveries increases risk, making cybersecurity strategies multi-layered.
While Muji is working to fully restore its services, the incident sends a clear message to every business: in the age of digital commerce, security is not an option — it is a necessity.
Source: www.bleepingcomputer.com
