Japan’s National Center of Incident Readiness and Strategy for Cybersecurity (NISC) urged small manufacturers to air-gap CNC job files after a Chiba Prefecture metal shop lost a weekend of production when ransomware encrypted a shared Windows server that also stored toolpath programs for three milling machines. The Otsuka-area shop—InfoHandle is withholding its trade name at the owner’s request—reported the incident to police and JPCERT/CC on Sunday night.

Attack path

According to a remediation firm the shop hired, attackers likely entered through a remote desktop port left open for a maintenance vendor, then moved laterally to the file server hosting G-code archives. Backup jobs ran to the same subnet; snapshots were deleted before operators noticed Monday morning alarms on a Nagano customer’s just-in-time order.

NISC’s Monday advisory does not name the shop but cites “a metalworking subcontractor in the Keiyo industrial belt” as the trigger. IPA separately warned that Qilin-branded ransomware crews have probed Japanese job shops since August, often demanding yen wire transfers through cryptocurrency mixers.

Production impact

The owner told InfoHandle he paid no ransom. Recovery required reloading programs machine-by-machine and re-probing fixtures. Two aerospace brackets shipped a day late; penalties were waived after customers accepted gap reports. Weekend overtime cost roughly 2.3 million yen in labor and scrap, he estimated.

NISC guidance

NISC recommends separating CNC program storage from office email networks, using hardware tokens for remote maintenance, and testing offline backups monthly. METI’s manufacturing cybersecurity pamphlets already describe similar controls, but uptake among ten-person shops remains spotty when vendors insist on always-on remote support.

Industry pattern

Japanese metal shops are dense in Chiba and Aichi, supplying automotive and defense tiers. Many run legacy Windows 7 interfaces on machine controllers even when office PCs upgrade. JPCERT/CC tickets for manufacturing ransomware doubled year-on-year in its July statistics release—not solely Qilin, but enough for NISC to elevate messaging ahead of fiscal year-end production pushes.

What owners should do this week

Operators should inventory which vendors still require open RDP, move G-code libraries to read-only NAS devices without internet routes, and print QR-coded contact sheets for JPCERT reporting. Insurance brokers report rising premiums for shops without documented air gaps. NISC will host a webinar with IPA on Thursday for Keiyo belt firms; attendance is free but registration requires a corporate email domain.

Vendor accountability

The maintenance vendor whose remote access was exploited issued a statement promising MFA rollout by October. The metal shop owner said he will require on-site visits for controller patches unless vendors accept jump boxes with session recording. METI’s supply-chain security working group lists similar clauses in model contracts released last spring.

Insurance and recovery

Business interruption riders on the shop’s policy excluded cyber events until a rider was added in 2025. Adjusters visited Monday to photograph air-gapped USB archives that saved partial programs. NISC’s webinar will cover insurance documentation because many owners discover coverage gaps only after attacks.

Peer networks

Chiba metal association chat groups shared NISC’s advisory within hours, attaching IPA checklists translated into plain Japanese. Larger tier-one suppliers told subcontractors they will score air-gap maturity in 2027 RFQs.

Law enforcement

Chiba police took a fraud report but have not named suspects; NISC avoided attributing the attack to a specific crew beyond referencing Qilin trends in IPA bulletins. Owners were told to preserve logs on offline USBs for possible future indictments.

IPA hotline counselors said call volume from metal shops rose Monday afternoon as owners double-checked backup schedules before accepting rush orders from automakers.

Controller legacy

Machine controllers running aging Windows interfaces cannot host endpoint agents; NISC reminded owners to isolate those networks even when vendors demand remote access for patches.

Regional banks that lend to the shop asked for updated business continuity plans before approving a seasonal credit line increase.

Machine tool dealers offered discounted offline backup appliances through month-end, citing NISC outreach.