Kintetsu World Express confirmed ransomware attack disrupted its systems
- Organization
- Kintetsu World Express
- Exploit
- Ransomware
- Industry
- Shipping & Logistics
Kintetsu World Express, a Tokyo-based freight forwarder that operates in more than 30 countries, reported a server failure on 23 April 2025 that disrupted services for some of its customers. On 28 April the company said its investigation had established the cause as unauthorised third-party access to its systems involving ransomware.
KWE set up an emergency response headquarters and engaged outside specialists to run a forensic investigation. In an update published on 30 April, the company said most of its systems remained fully functional and that its teams were able to support customers with minimal disruption while it remediated and recovered the affected systems.
The company did not identify the group responsible, did not say whether a ransom had been demanded, and did not disclose whether any data had been copied. It said it would notify customers directly if it determined their data had been affected, and that it was reviewing its environment with external IT partners.
It was the second security incident tied to KWE in roughly a year. In April 2024 a threat actor using the name 888 claimed to have obtained data belonging to hundreds of the company's clients. As of the start of May 2025 the ransomware investigation remained open and KWE had made no statement about the scope of any data loss.