← Blog

Japan Times: Unverified Eclipse Ransomware Leak Claim

Share on X

Unverified claim: Ransomware trackers including Ransomware.live and secondary writeups such as HookPhish show the group Eclipse listing The Japan Times (japantimes.co.jp) around September 30, 2026. At indexing time BreachHistory found no company confirmation, regulator filing, or attested subscriber census. This post catalogs a named media-brand extortion listing — it does not treat actor marketing as fact.

Canonical: https://breachhistory.com/japan-times/japan-times-eclipse2026.

What the listing says — and what it does not

Public tracker summaries identify the victim, group, and discovery timestamp. They do not supply a verified file inventory, ransom amount, or confirmation that production newsroom systems were encrypted. Until The Japan Times speaks, assume uncertainty.

Why we still catalog it

From June 2026 BreachHistory indexes named ransomware/extortion leak-site claims when the victim is identifiable, clearly labeled unverified. A major English-language newspaper in Japan clears that bar. Subscribers should watch for phishing that spoofs renewal desks, not panic about unconfirmed archive dumps.

Action items

  1. Ignore “pay to stop Japan Times leak” messages.
  2. Verify any breach email against japantimes.co.jp official domains.
  3. Subscribers: rotate passwords if you reuse them elsewhere; enable MFA.
  4. Journalists: wait for a company statement before writing confirmed-impact copy.

Related Japan 2026 context

Verified neighbors include Times Car’s 6.6M account breach and Aflac Japan. Those are company-attested. Eclipse’s Japan Times listing is not — keep the labels straight.

Technical depth and open questions

Public sources rarely ship full packet captures. Readers should separate three layers: (1) what the victim or regulator attested, (2) what reputable press quoted from those attestations, and (3) what actors claimed on leak sites. Mixing the layers is how unverified counts become “facts” in viral posts. For this incident, stick to layer one and two unless a sentence is explicitly marked as an actor claim.

Open questions usually include exact malware family, full population beyond the first filing, whether backups were hit, and whether downstream vendors were entry points. Absence of answers is normal in week one. It is not permission to invent them.

Phishing and social-engineering playbook to expect

Expect lookalike domains, fake “incident response” WhatsApp accounts, and urgency around deadlines that do not appear in official letters. Ask for a ticket number and hang up; call the number printed on a prior legitimate statement. Do not install remote-support tools. Do not pay cryptocurrency to strangers who claim they can delete your file from a dump.

Employees should treat internal IT tickets that arrive only by SMS as hostile. Vendors should verify purchase-order changes by phone using a known number, not the number in the email signature block.

How this compares to neighboring BreachHistory rows

Cross-read related finance, healthcare, and ransomware claim posts already on BreachHistory for pattern recognition — shared vendor risk, short access windows, and delayed consumer mailings show up again and again in 2026. Use those comparisons to brief executives, not to copy unverified counts from one row into another.

When regulators publish a revised census or the victim issues a post-mortem, the catalog row and this blog’s canonical link are the places to watch. Screenshots age badly; URLs that we update do not.

Checklist for security teams

  1. Inventory every “non-core” system that still stores customer or patient identifiers.
  2. Require phishing-resistant MFA on those systems.
  3. Log and alert on bulk exports.
  4. Pre-draft customer notice templates approved by counsel.
  5. Tabletop a 72-hour extortion email scenario with legal and PR in the room.

Those five steps are cheaper than learning them during an all-hands on a national holiday.

Additional context for readers tracking this incident: verified notices beat rumor screenshots. Bookmark the canonical BreachHistory URL and re-check after regulator updates. Secondary phishing usually peaks in the first two weeks after headlines — verify every unexpected call against a published hotline. If you received a letter, enroll in offered monitoring and still freeze credit where SSNs are in scope. If you did not receive a letter but believe you are in the population, ask the organization in writing and keep a copy of your inquiry. Journalists should cite primary notices and reputable trade press, never Breachsense, and should label unverified leak-site claims clearly in the lede.

Additional context for readers tracking this incident: verified notices beat rumor screenshots. Bookmark the canonical BreachHistory URL and re-check after regulator updates. Secondary phishing usually peaks in the first two weeks after headlines — verify every unexpected call against a published hotline. If you received a letter, enroll in offered monitoring and still freeze credit where SSNs are in scope. If you did not receive a letter but believe you are in the population, ask the organization in writing and keep a copy of your inquiry. Journalists should cite primary notices and reputable trade press, never Breachsense, and should label unverified leak-site claims clearly in the lede.

Additional context for readers tracking this incident: verified notices beat rumor screenshots. Bookmark the canonical BreachHistory URL and re-check after regulator updates. Secondary phishing usually peaks in the first two weeks after headlines — verify every unexpected call against a published hotline. If you received a letter, enroll in offered monitoring and still freeze credit where SSNs are in scope. If you did not receive a letter but believe you are in the population, ask the organization in writing and keep a copy of your inquiry. Journalists should cite primary notices and reputable trade press, never Breachsense, and should label unverified leak-site claims clearly in the lede.

Additional context for readers tracking this incident: verified notices beat rumor screenshots. Bookmark the canonical BreachHistory URL and re-check after regulator updates. Secondary phishing usually peaks in the first two weeks after headlines — verify every unexpected call against a published hotline. If you received a letter, enroll in offered monitoring and still freeze credit where SSNs are in scope. If you did not receive a letter but believe you are in the population, ask the organization in writing and keep a copy of your inquiry. Journalists should cite primary notices and reputable trade press, never Breachsense, and should label unverified leak-site claims clearly in the lede.

Additional context for readers tracking this incident: verified notices beat rumor screenshots. Bookmark the canonical BreachHistory URL and re-check after regulator updates. Secondary phishing usually peaks in the first two weeks after headlines — verify every unexpected call against a published hotline. If you received a letter, enroll in offered monitoring and still freeze credit where SSNs are in scope. If you did not receive a letter but believe you are in the population, ask the organization in writing and keep a copy of your inquiry. Journalists should cite primary notices and reputable trade press, never Breachsense, and should label unverified leak-site claims clearly in the lede.

Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.

Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.

Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.

Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.

Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.

Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.

Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.

Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.

Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.

Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.

Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.

Further reading and monitoring advice: enable credit freezes where national ID or SSN exposure is attested; monitor account statements weekly for 90 days; tell household members about the incident so they do not fall for secondary scams aimed at your relatives; and keep paper copies of notices. Organizations should publish a single official FAQ URL and refuse to discuss case specifics over unverified social DMs. Researchers should avoid republishing sample PII from extortion emails. Policymakers reading this file should note how often partner and employee-support tools — not the hardened channel — drive the census.