Kadokawa and Niconico Ransomware Attack: Timeline, Impact and Lessons
The 2024 cyberattack on Kadokawa and Niconico, orchestrated by the hacker group BlackSuit, disrupted services and leaked the personal data of over 254,000 users. Beginning on June 8, 2024, this ransomware attack forced Kadokawa to shut down services, leading to significant operational and financial setbacks. The breach exposed vulnerabilities in Japan's cybersecurity landscape, primarily due to phishing tactics. In response, Kadokawa and Niconico implemented enhanced security measures and rebuilt systems to restore operations by August 5, 2024. This incident underscores the critical need for stronger cyber defenses and proactive strategies against ransomware attacks.
Quick answer: In early June 2024, a ransomware attack disrupted Japanese publisher Kadokawa and its video platform Niconico, which went offline for weeks. The BlackSuit group claimed responsibility and later published stolen data after Kadokawa did not pay. Niconico services returned in stages, with the main service back in early August 2024. Lessons: segmentation, tested backups, and practised recovery.
Key takeaways
- The attack began around 8 June 2024 and took Niconico and several Kadokawa services offline.
- BlackSuit claimed it and leaked data after a ransom deadline passed without payment, according to reported accounts.
- Recovery took weeks, with Niconico services returning in stages from early August 2024.
- The pattern is typical of ransomware: encryption plus data theft, a leak threat and slow rebuilding.
- Prioritised recovery plans, offline backups and network segmentation limit how long a platform stays dark.
- Details here come from public reporting. Check Kadokawa's own notices for official figures.
Who are Kadokawa and Niconico?
Kadokawa Corporation is a large Japanese publishing and media group. Niconico is a Japanese video-sharing and live streaming service run by Dwango, a Kadokawa subsidiary, known for comments displayed over the video. Because many creators and viewers depend on it, an outage is visible to the public, which is part of why attackers target such firms.
What is the timeline?
| Date (2024) | What was reported |
|---|---|
| 8 June | Early morning failures hit Niconico and other Kadokawa services. Systems were shut down to contain the problem. |
| 9 June onwards | Kadokawa announced a cyberattack, said it had reported it to authorities, and kept affected systems isolated. |
| Mid June | The company confirmed ransomware, and the BlackSuit group claimed responsibility, saying it had stolen a large volume of data. |
| Late June to early July | A ransom deadline passed without payment, and the group began publishing stolen data, as reported. |
| July | Niconico used a temporary site to keep users informed. Some live programming was cancelled during recovery. |
| Early August | Niconico services were restored in stages, with the main service reported back on 5 August. |
The exact times, volumes of data and later counts of affected people were revised as the investigation continued, so use Kadokawa's official statements and reliable news reports for numbers. We have not repeated the figures that circulated early.
What was the impact?
- Service outage. Niconico and linked services went offline for weeks, and some Kadokawa business systems, such as the online shop and production, were disrupted.
- Publishing. Printing and distribution of some books and e-books was delayed.
- Data exposure. Stolen data was leaked after the ransom was not paid, which raises privacy and legal consequences for employees, partners and users.
- Financial and reputational cost. The company reported financial effects, and share price movement was widely commented on. Treat any single figure as reported, not audited.
Why did recovery take so long?
Modern ransomware groups rarely only encrypt. They steal data first and often attack backups. Once servers are encrypted and the attacker still has access, a company may need to rebuild systems from clean images, reset credentials everywhere and confirm that the intruder is out before reconnecting services. Reports said the attackers took actions that forced engineers to disconnect equipment physically. That is a reason to treat containment, not only restoration, as the first priority.
What should a streaming or media platform prioritise in recovery?
- Contain first. Isolate affected segments, disable compromised accounts and preserve logs and disk images for investigation.
- Restore identity. Rebuild directory services and rotate privileged credentials before bringing anything else online.
- Restore in tiers. Bring back authentication and billing, then core streaming, then secondary features. Decide this order in advance.
- Communicate. Run a status page on infrastructure that is independent of the affected network, as Niconico did with a temporary site.
- Handle the data. Notify regulators and affected people as law requires, and monitor leak sites for the organisation's data.
What defences reduce the risk?
- Offline or immutable backups, and regular restore tests that measure how long recovery really takes.
- Network segmentation so one foothold cannot reach every system, including between subsidiaries.
- Multi-factor authentication on remote access and administrators, and tight control of privileged accounts.
- Patching of internet-facing systems, and monitoring for unusual data transfers.
- A rehearsed incident response plan with legal, communications and technical roles, including a decision process for ransom demands. Authorities generally advise against paying.
The No More Ransom project offers decryptors for some ransomware families and guidance. Indian organisations should also be aware of CERT-In reporting duties. For comparable events, read latest ransomware attacks and what we can learn and the Japan Airlines cyberattack.
Next steps
To build the skills for containment and recovery, see WebAsha's incident handler training.
Related reading
Frequently Asked Questions
What's Your Reaction?
Like
1
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0