Weekday Japan business intelligence for finance professionals.

Join the list
Tokyo Brief東 京 ブ リ ー フ

Japan's day, wrapped and delivered by morning.

Article

Asahi Group Says Ransomware Attack Broke Its Financial Reporting Controls

A ransomware attack in September that let an intruder roam Asahi Group Holdings' Japan network delayed the brewer's annual securities report by four months and forced a rare admission that its internal controls over financial reporting were not effective for the year to December 2025, even though auditors signed off on the underlying numbers.

Jul 27, 20263 min readASAHI GROUP HOLDINGS,LTD.2502
A darkened data center aisle with server racks and a technician unplugging a network cable, symbolizing a corporate ransomware breach.

Asahi Group Holdings told the Kanto Local Finance Bureau on July 27, 2026 that its internal controls over financial reporting for the year to December 2025 were not effective. The reason is not an accounting error. It is a ransomware attack that hit the brewer's Japan operations the previous September and exposed how loosely the company managed who could get administrator access to its own systems.

What went wrong

Early on September 29, 2025, systems that Asahi's Japan region runs and manages failed. An investigation found that data on several servers had been encrypted, confirming a cyberattack. Asahi says an intruder obtained administrator credentials without authorization, used the stolen accounts to explore its internal network, and then deployed ransomware across multiple servers. The company cut internal and external network connections and isolated its data centers on the day of the attack, and stood up an emergency response team under its business-continuity plan. It says the damage was confined to systems its Japan region operates.

Restoring access to accounting data, and relying on substitute manual processes while the network was rebuilt, took long enough that Asahi could not finish the data checks its year-end close required on schedule. That forced the extension of the deadline for its annual securities report, first disclosed to markets on March 25, 2026 and ultimately pushed back to July 27, 2026. Asahi filed the report with the Kanto Local Finance Bureau on that date, and the company's Group CEO apologized to shareholders and other stakeholders for the disruption.

Asahi traces the failure to its Japan region's own rulebook: its information-system and security regulations spelled out access controls and technical safeguards against attack, but the company says operational management of those rules, including who held administrator privileges, was not fully carried out across part of the systems staff use daily. That gap let the attacker in, and its effect on disclosure timing was serious enough that Asahi rated its company-wide policy for IT-systems controls as a material weakness. The company says every correction the incident required is already reflected in its consolidated financial statements, which its auditors signed off with an unqualified opinion, a judgment on the numbers themselves rather than on the controls that produced them.

The fix, so far

Asahi lists three remediation steps under way: tightening access management and password rules across every system inside the scope of its internal-control review; standing up monitoring under its Information Security Committee to track rule compliance across the Japan region; and running a "Fit & Gap" analysis, checking what its security policies require against what its most important systems actually do. The company has not given a date for finishing that review.

The delayed filing, Asahi's 102nd annual securities report, also carries XBRL-tagged revenue data spanning recent years: group revenue climbed from ¥2.24tn in 2021 to ¥2.94tn in 2024.

Asahi Group Holdings revenue, 2021-2024
Revenue reported under IFRS, tagged in XBRL data filed with Asahi's annual securities report for the year to December 2025.
Fiscal yearIFRS revenue
2021¥2.24tn
2022¥2.51tn
2023¥2.77tn
2024¥2.94tn