Cyber Incident Victim: 株式会社トーモク
Date:
May 2025
Location:
Japan
Summary
株式会社トーモク reported that a ransomware attack encrypted several of its servers, disrupting the online ordering system while other services remained operational. The company stated that fax and email ordering, as well as its website and email infrastructure, continued to function normally, allowing production to proceed without interruption. Investigations into the full scope of the incident are ongoing, with external specialists and law enforcement assisting in containment and recovery efforts. Full restoration of the affected systems is expected to take additional time.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On May 3, 2025, a ransomware attack encrypted several servers belonging to the Tomoku group, prompting the company to detect the intrusion and begin assessing the impact. The incident was disclosed to stakeholders in a notice issued on May 8, 2025, which described the event as a ransomware‑induced system failure. According to the notice, the online ordering system that relies on direct connection to the company’s servers experienced a disruption as a result of the encryption. At the time of the notice, the full scope of the damage was still under investigation, with the company indicating that other potential harms were being examined. The notice emphasized that the encryption had affected only a subset of the group’s servers, leaving other infrastructure components untouched. No further technical details about the ransomware variant or the attack vector were provided in the notice.

Despite the disruption to the online ordering system, the notice confirmed that web‑based ordering, fax‑based ordering, email‑based ordering, and the corporate homepage remained fully accessible and operational. Normal production activities continued unaffected by the incident, as the company’s manufacturing processes were not reliant on the compromised servers. Tomoku expressed regret for the inconvenience caused to customers, partners, and other stakeholders, offering a sincere apology for the concern and disruption. To address the incident, the company engaged external cybersecurity specialists and coordinated with law‑enforcement authorities to conduct a thorough investigation, implement protective measures, and restore the affected systems. The notice stated that complete recovery would require additional time, but that ongoing work was underway to bring the encrypted servers back to service. Tomoku committed to communicating any newly discovered facts through its website or other official channels as they become available.
