Kadokawa and Niconico Ransomware Attack: Timeline, Impact and Lessons

The 2024 cyberattack on Kadokawa and Niconico, orchestrated by the hacker group BlackSuit, disrupted services and leaked the personal data of over 254,000 users. Beginning on June 8, 2024, this ransomware attack forced Kadokawa to shut down services, leading to significant operational and financial setbacks. The breach exposed vulnerabilities in Japan's cybersecurity landscape, primarily due to phishing tactics. In response, Kadokawa and Niconico implemented enhanced security measures and rebuilt systems to restore operations by August 5, 2024. This incident underscores the critical need for stronger cyber defenses and proactive strategies against ransomware attacks.

Dec 31, 2024 - 10:17
Updated: 7 days ago
111.8k
Kadokawa and Niconico Ransomware Attack: Timeline, Impact and Lessons

Quick answer: In early June 2024, a ransomware attack disrupted Japanese publisher Kadokawa and its video platform Niconico, which went offline for weeks. The BlackSuit group claimed responsibility and later published stolen data after Kadokawa did not pay. Niconico services returned in stages, with the main service back in early August 2024. Lessons: segmentation, tested backups, and practised recovery.

Key takeaways

  • The attack began around 8 June 2024 and took Niconico and several Kadokawa services offline.
  • BlackSuit claimed it and leaked data after a ransom deadline passed without payment, according to reported accounts.
  • Recovery took weeks, with Niconico services returning in stages from early August 2024.
  • The pattern is typical of ransomware: encryption plus data theft, a leak threat and slow rebuilding.
  • Prioritised recovery plans, offline backups and network segmentation limit how long a platform stays dark.
  • Details here come from public reporting. Check Kadokawa's own notices for official figures.

Who are Kadokawa and Niconico?

Kadokawa Corporation is a large Japanese publishing and media group. Niconico is a Japanese video-sharing and live streaming service run by Dwango, a Kadokawa subsidiary, known for comments displayed over the video. Because many creators and viewers depend on it, an outage is visible to the public, which is part of why attackers target such firms.

What is the timeline?

Date (2024)What was reported
8 JuneEarly morning failures hit Niconico and other Kadokawa services. Systems were shut down to contain the problem.
9 June onwardsKadokawa announced a cyberattack, said it had reported it to authorities, and kept affected systems isolated.
Mid JuneThe company confirmed ransomware, and the BlackSuit group claimed responsibility, saying it had stolen a large volume of data.
Late June to early JulyA ransom deadline passed without payment, and the group began publishing stolen data, as reported.
JulyNiconico used a temporary site to keep users informed. Some live programming was cancelled during recovery.
Early AugustNiconico services were restored in stages, with the main service reported back on 5 August.

The exact times, volumes of data and later counts of affected people were revised as the investigation continued, so use Kadokawa's official statements and reliable news reports for numbers. We have not repeated the figures that circulated early.

What was the impact?

  • Service outage. Niconico and linked services went offline for weeks, and some Kadokawa business systems, such as the online shop and production, were disrupted.
  • Publishing. Printing and distribution of some books and e-books was delayed.
  • Data exposure. Stolen data was leaked after the ransom was not paid, which raises privacy and legal consequences for employees, partners and users.
  • Financial and reputational cost. The company reported financial effects, and share price movement was widely commented on. Treat any single figure as reported, not audited.

Why did recovery take so long?

Modern ransomware groups rarely only encrypt. They steal data first and often attack backups. Once servers are encrypted and the attacker still has access, a company may need to rebuild systems from clean images, reset credentials everywhere and confirm that the intruder is out before reconnecting services. Reports said the attackers took actions that forced engineers to disconnect equipment physically. That is a reason to treat containment, not only restoration, as the first priority.

What should a streaming or media platform prioritise in recovery?

  1. Contain first. Isolate affected segments, disable compromised accounts and preserve logs and disk images for investigation.
  2. Restore identity. Rebuild directory services and rotate privileged credentials before bringing anything else online.
  3. Restore in tiers. Bring back authentication and billing, then core streaming, then secondary features. Decide this order in advance.
  4. Communicate. Run a status page on infrastructure that is independent of the affected network, as Niconico did with a temporary site.
  5. Handle the data. Notify regulators and affected people as law requires, and monitor leak sites for the organisation's data.

What defences reduce the risk?

  • Offline or immutable backups, and regular restore tests that measure how long recovery really takes.
  • Network segmentation so one foothold cannot reach every system, including between subsidiaries.
  • Multi-factor authentication on remote access and administrators, and tight control of privileged accounts.
  • Patching of internet-facing systems, and monitoring for unusual data transfers.
  • A rehearsed incident response plan with legal, communications and technical roles, including a decision process for ransom demands. Authorities generally advise against paying.

The No More Ransom project offers decryptors for some ransomware families and guidance. Indian organisations should also be aware of CERT-In reporting duties. For comparable events, read latest ransomware attacks and what we can learn and the Japan Airlines cyberattack.

Next steps

To build the skills for containment and recovery, see WebAsha's incident handler training.

Related reading

Frequently Asked Questions

The BlackSuit ransomware group claimed responsibility for the June 2024 attack and later published stolen data, according to public reports. Attribution of ransomware groups can change as investigations continue, so check official statements.

Niconico is a Japanese video-sharing and live streaming platform operated by Dwango, a subsidiary of the Kadokawa group. It is known for viewer comments overlaid on videos and has a large user base in Japan.

Niconico was offline for weeks after the attack began around 8 June 2024. Services returned in stages, with the main service reported back in early August 2024. Check Kadokawa's notices for exact dates.

Reports said the company did not pay, and the attackers then published stolen data. Authorities generally advise against paying, but each organisation must decide with legal and incident response advice.

It encrypts systems and often steals data first, then demands payment for a decryptor and for not leaking the data. The result is downtime, recovery cost, legal duties and loss of trust.

Keep tested offline backups, segment networks, use MFA on remote and admin access, patch internet-facing systems, monitor for data theft and rehearse an incident response plan with a recovery order agreed in advance.

What's Your Reaction?

Like Like 1
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.