Qilin & Asahi: When a “Standard” Ransomware Attack Shuts Down 30 Factories

CTI

Visuel Asahi 1

When Qilin compromised Asahi Group Holdings in late September 2025, nothing unusual happened. That’s precisely the point.

No zero-day exploit. No nation-state sophistication. A set of compromised credentials, a well-documented RaaS playbook, and within days: 30 factories offline, 6 breweries shut down for a week, allegedly 27 gigabytes of data exfiltrated, and more than $31 million in lost revenue, before legal exposure and incident response costs were even counted.

The Asahi case is not a cautionary tale about an exotic threat. It’s a case study in what the current ransomware baseline looks like in 2025, and why it still works.

Qilin: A Maturing RaaS Operation with a Clear Business Model

Qilin has been active since July 2022, a relatively recent entrant, but now one of the most prolific ransomware operations in the ecosystem. As of today, the group has claimed approximately 1,800 victims across its primary target sectors: manufacturing, healthcare, and technology services, with a concentration in the US, UK, Canada, France, and Italy.

The group operates as a Ransomware-as-a-Service (RaaS), which means Qilin’s operators develop and maintain the ransomware infrastructure while affiliates, external threat actors who lease access to the toolkit, conduct the actual attacks. The model fragments attribution: we know the ransomware, but rarely who deployed it. Some actors identified using Qilin’s infrastructure include North Korea-sponsored intrusion sets, which illustrates how the affiliate model extends well beyond the criminal ecosystem.

The financial structure reinforces high-value targeting. Qilin operates on a revenue split tied to a $3 million threshold: ransoms above that amount give affiliates 85% of the proceeds. That incentive structure pushes affiliates toward large, high-visibility targets, organizations with enough at stake to consider paying.

Qilin’s ransom amounts are never publicly disclosed on their data leak site, which is atypical in the ecosystem. The Synovis case, a UK healthcare provider targeted in 2024, gives a reference point: Qilin demanded $50 million. Synovis did not pay, and ultimately spent $40 million over 18 months to restore their systems.

How Qilin Gets In and How They Stay

Unlike many ransomware operations that rely on phishing or vulnerability exploitation as the primary entry vector, Qilin’s initial access method is primarily based on compromised credentials. These can be sourced from infostealer logs circulating on dark web marketplaces, or purchased from Initial Access Brokers, specialists who acquire credentials and sell them to other threat actors.

Explore how Citalid maps and tracks the threat actors targeting your sector

EXPLORE THREAT EXPOSURE

Once inside, Qilin deploys a double extortion strategy: data exfiltration combined with ransomware encryption. Victims face two simultaneous threats, losing access to their systems and having their sensitive data published on Qilin’s data leak site if the ransom is not paid.

The ransomware itself includes features specifically designed in particular to maximize pressure:

  • A claimed backup deletion capability, preventing victims from restoring data without paying
  • A Call lawyer module an internal function that helps affiliates and operators leverage data protection regulation exposure in negotiations, turning potential GDPR or equivalent sanctions into an additional financial pressure point during ransom discussions

This last element is part of what Lorena Michoud, CTI Analyst at Citalid, describes as an emerging trend: cybercriminal lawfare, where intrusion sets incorporate legal threats into ransom demands to weaponize data protection regulation exposure.

The Asahi Incident: What Actually Happened

The attack on Asahi Group Holdings began on September 29, 2025. According to Asahi’s disclosure, attackers compromised network equipment to gain access to the data center network, then encrypted multiple active servers and connected devices.

In early October, Asahi notified Japanese authorities. Shortly after, Qilin claimed the attack and announced the exfiltration of 27 gigabytes of data, approximately 10,000 files. They published around 30 screenshots of sensitive documentation as proof: profit and loss statements, equity information, tax returns, and, with some irony, extracts from a cybersecurity audit report. Personal information of employees was also included.

The operational impact was immediate and visible:

  • Order processing, shipments, and deliveries were suspended
  • The accounting system failed
  • The vast majority of Asahi’s 30 Japanese factories and 6 of 7 breweries shut down for a week
  • Distributors began exploring alternatives with competitors including Kirin and Suntory

It took two months to fully contain the attack and restore systems. Nearly 2 million personal information records, customers, employees, retirees, were ultimately confirmed as exposed.

One important nuance: not all operational disruptions were necessarily caused directly by the ransomware. A significant share likely resulted from Asahi’s own mitigation decisions, disconnecting systems and isolating networks to prevent lateral movement. As Lorena Michoud noted during the session, this dynamic is frequently observed: the Jaguar Land Rover case is a good example, as the strongest operational impacts were caused by the mitigation measures.

The Financial Picture: What’s Actually at Stake

Asahi confirmed a revenue loss exceeding $31 million attributable to production shutdown alone. With more than 6 million bottles produced per day, a single week of disruption translates to at least 42 million bottles of lost output.

But the $31 million figure is a floor, not a ceiling. The full financial exposure includes:

  • Incident response costs: Not yet disclosed, spent $40 million over 18 months on recovery.
  • Regulatory exposure: Asahi confirmed 2 million personal records were exposed. Japan’s data protection framework allows fines of up to $700,000 in such cases, a limited sanction by comparison to the GDPR, which would allow up to $80 million for a company with Asahi’s €2 billion turnover.
  • Reputational and commercial tail: Distributors actively exploring competitor alternatives during disruption creates a long-term commercial risk that doesn’t appear on an incident response invoice.
  • Stock price: A modest impact was observed between September 29 and October 8, though Asahi’s stock was already on a declining trend. Market reaction to cyberattacks is typically muted in the short term, the medium-term effects are harder to isolate.

The incident is also not closed. Legal proceedings and regulatory determinations can take up to two years to finalize.

Why Manufacturing Is a Preferred Target

The Asahi incident is not an anomaly for the manufacturing sector. The convergence of operational technology (OT) and information technology (IT) in modern manufacturing environments creates structural exposure:

  • A larger and more heterogeneous attack surface, with more connected devices and legacy systems
  • More employees and third-party access points, each a potential credential compromise
  • A known pool of documented vulnerabilities associated with industrial control systems
  • High dependency on continuous operations, where any interruption carries immediate, measurable cost
  • Supply chain interdependencies that can cascade a single incident into sector-wide disruption

For Qilin and similar RaaS operations, a manufacturing target like Asahi represents exactly what their affiliate incentive structure optimizes for: an organization where operational paralysis is immediate, visible, and costly, and where the pressure to restore operations quickly is maximum.

Frequently Asked Questions

Does paying the ransom make sense?

No, and not only for ethical reasons. Paying flags your organization as a target willing to pay, which increases the likelihood of future attacks. It does not guarantee the decryption key will work, that attackers have fully left the system, or that exfiltrated data will be deleted. In the Synovis case, the organization chose not to pay and spent $40M on recovery, roughly equivalent to Qilin’s ransom demand, but without funding the criminal operation.

Was Asahi specifically targeted or an opportunistic victim?

Probably both. Qilin operates at the intersection of targeted and opportunistic attacks. Their credential-based initial access method is inherently opportunistic, they act on whatever credentials are available. But Asahi’s profile (global brand, manufacturing sector, high media visibility) makes it an attractive target for affiliates seeking high-value ransoms. We cannot confirm intentional targeting.

Is AI changing the threat landscape?

Not structurally, at least not yet. AI makes certain tasks easier for attackers (phishing personalization, operational efficiency), but it is not a game-changer in current attack patterns. The dominant vectors remain credential compromise, unpatched vulnerabilities, and phishing. The basics still matter most.

What is the “Call Lawyer” module?

An internal Qilin capability that helps affiliates and operators incorporate data protection regulation exposure into ransom negotiations, essentially using the threat of regulatory sanctions as an additional financial lever against victims. It is part of a broader trend of cybercriminal lawfare.

Webinar

Watch the Threat Signal EP01 replay to hear the full analysis from Lorena Michoud

Get the replay

More content

Related content