Asahi Group has detailed the scale of the data breach caused by the ransomware attack that disrupted its systems two months ago.
The Japan-headquartered company said 1.9m sets of personal information were compromised or potentially exposed. The intrusion, which involved ransomware deployed across multiple servers, originated via network equipment at one of Asahi’s domestic sites.
According to the latest update, the exposed data includes customer service contacts (1.5m records), external contacts receiving ceremonial telegrams (114,000), employees and retirees (107,000), and their family members (168,000). The brand owner noted that no credit card information was affected and there is no evidence so far of data being published online.
In a further statement released today (27 November), Asahi said the system disruption has delayed the publication of its third-quarter results, which were originally due on 12 November. A new reporting date will be set once system restoration has been completed and financial data can be verified.
The group issued a progress report covering its ‘Europe’ and ‘Asia Pacific’ segments for the nine months to the end of September. Sales in ‘Europe’ were down in the period by 3% year on year amid subdued consumption and poor summer weather, while ‘Asia Pacific’ revenues grew 3.1% thanks to stronger non-alcohol sales in Oceania and South-East Asia.
Asahi said its “forensic” review, security enhancements and phased system recovery are ongoing. CEO Atsushi Katsuki apologised for the disruption and said the group remains confident in its medium- and long-term strategy, despite short-term pressure on its Japan operations.




