Asahi Group Holdings told the Kanto Local Finance Bureau on July 27, 2026 that its internal controls over financial reporting for the year to December 2025 were not effective. The reason is not an accounting error. It is a ransomware attack that hit the brewer's Japan operations the previous September and exposed how loosely the company managed who could get administrator access to its own systems.
What went wrong
Early on September 29, 2025, systems that Asahi's Japan region runs and manages failed. An investigation found that data on several servers had been encrypted, confirming a cyberattack. Asahi says an intruder obtained administrator credentials without authorization, used the stolen accounts to explore its internal network, and then deployed ransomware across multiple servers. The company cut internal and external network connections and isolated its data centers on the day of the attack, and stood up an emergency response team under its business-continuity plan. It says the damage was confined to systems its Japan region operates.
Restoring access to accounting data, and relying on substitute manual processes while the network was rebuilt, took long enough that Asahi could not finish the data checks its year-end close required on schedule. That forced the extension of the deadline for its annual securities report, first disclosed to markets on March 25, 2026 and ultimately pushed back to July 27, 2026. Asahi filed the report with the Kanto Local Finance Bureau on that date, and the company's Group CEO apologized to shareholders and other stakeholders for the disruption.
Asahi traces the failure to its Japan region's own rulebook: its information-system and security regulations spelled out access controls and technical safeguards against attack, but the company says operational management of those rules, including who held administrator privileges, was not fully carried out across part of the systems staff use daily. That gap let the attacker in, and its effect on disclosure timing was serious enough that Asahi rated its company-wide policy for IT-systems controls as a material weakness. The company says every correction the incident required is already reflected in its consolidated financial statements, which its auditors signed off with an unqualified opinion, a judgment on the numbers themselves rather than on the controls that produced them.
The fix, so far
Asahi lists three remediation steps under way: tightening access management and password rules across every system inside the scope of its internal-control review; standing up monitoring under its Information Security Committee to track rule compliance across the Japan region; and running a "Fit & Gap" analysis, checking what its security policies require against what its most important systems actually do. The company has not given a date for finishing that review.
The delayed filing, Asahi's 102nd annual securities report, also carries XBRL-tagged revenue data spanning recent years: group revenue climbed from ¥2.24tn in 2021 to ¥2.94tn in 2024.
| Fiscal year | IFRS revenue |
|---|---|
| 2021 | ¥2.24tn |
| 2022 | ¥2.51tn |
| 2023 | ¥2.77tn |
| 2024 | ¥2.94tn |
