HomeSecurityBlackfield: Demands $2 million from Nidec after ransomware attack

Blackfield: Seeks $2 million from Nidec after ransomware attack

The Japanese company Nidec Corporation , one of the world's largest manufacturers of electric motors and electronic components, has been targeted by cybercriminals . The Blackfield ransomware group has claimed responsibility for the attack, demanding a ransom of $2 million and threatening to release or sell the data it claims to have removed from the company's information systems.

Blackfield Nidec ransomware

The case adds to the ever-growing list of attacks against large industrial organizations, demonstrating that manufacturing businesses continue to be a key target for ransomware groups due to their enormous economic importance and the value of the data they manage.

Nidec and its role in the international industry

Nidec is one of the world's leading manufacturers of electric motors. Its portfolio ranges from tiny, high-precision motors used in smartphones, hard drives and electronic devices to large industrial motors for robotics, elevators and heating, ventilation and air conditioning systems.

At the same time, the company plays a key role in the automotive industry, developing engines for electric vehicles, electric power steering systems and advanced driver assistance systems (ADAS) technologies.

See also: Iran's cyberattacks on Israel tripled in a year

With more than 100,000 employees, a presence in more than 40 countries and an annual turnover exceeding 17 billion dollars, Nidec is considered one of Japan's most important industrial companies.

The attack originated from the subsidiary in Taiwan

According to the company's official announcement , the incident was detected on June 22, 2026 and concerns the Nidec subsidiary Chaun Choung Technology , based in Taiwan.

Management confirmed that part of the company's servers were affected by a ransomware attack, resulting in immediate activation of incident response plans.

As a first protective measure, security officials disconnected the affected servers and isolated parts of the corporate networkto limit the spread of the attack to other information systems.

Although the investigation is still ongoing, Nidec admits that there is a possibility of information leakage, but the exposure of personal or confidential data.

Blackfield: Seeks $2 million from Nidec after ransomware attack

The Blackfield team's requirements

A few days after the incident was revealed, the Blackfield group published a related post on its dark web leak site, claiming responsibility for the attack.

The cybercriminals claim to have removed a significant amount of corporate data and are giving Nidec more than two weeks to enter into negotiations, otherwise they threaten to make the files public or sell them to third parties.

See also: Nissan: Employee data breach via Oracle PeopleSoft vulnerability

The demand for the deletion of the allegedly stolen data is $2 million. At the same time, the group proceeded with the unusual practice of offering a one-day extension to the leak deadline in exchange for $5,000.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

In addition, it published a link through which interested parties can theoretically purchase the data for $400,000, a tactic increasingly used by ransomware groups to increase pressure on victims.

Sample files without verification of authenticity

To bolster its claims, Blackfield has released samples of files and folders purportedly from IT systems . However, the authenticity of the material, nor the actual volume of data that may have been removed, has not yet been independently confirmed.

The company is continuing its digital forensic investigation to determine whether there was an actual leak of sensitive information and which parts of the infrastructure were affected.

It's not the first time

The new attack is not an isolated incident for the Japanese group. In October 2024, another Nidec subsidiary, based in Vietnam, was also hit by a ransomware attack, which led to the leak of more than 50,000 company files.

At the time, the 8Base  and Everest groups claimed responsibility , attempting to extort the company independently of each other, demonstrating that large industrial organizations can be simultaneously targeted by different criminal groups.

See also: The renewed Millennium RAT has infected over 62,000 devices

Blackfield: Seeks $2 million from Nidec after ransomware attack

Industrial companies remain at the center of attacks

In recent years, ransomware attacks have increasingly targeted the industrial sector, as production disruption can cause huge financial losses in just a few hours. This significantly increases the pressure on businesses to even consider paying the ransom.

The Nidec case highlights once again the need for continued investment in cybersecurity, industrial network protection and incident. As ransomware groups continue to evolve their methods, businesses are urged to strengthen both technical defenses and recovery processes to limit the impact of future attacks.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS