Asahi Says Cyber Attack Caused Internal Control Weakness, Delays Filing
Asahi disclosed a material weakness in internal controls for the fiscal year ending December 2025 after a cyberattack in September 2025 compromised its systems. Attackers gained administrator privileges and deployed ransomware, disrupting access to financial data and forcing the company to delay submission of its securities report. The company assessed that internal controls over Japan region IT operations were ineffective.
Cyber Attack Impact on Financial Reporting
On September 29, 2025, a system failure occurred early morning in Asahi's Japan region. Investigation revealed that some server data was encrypted, confirming a ransomware cyberattack. The attackers gained unauthorized administrator privileges, explored internal networks, and executed ransomware on multiple servers. To contain the damage, the company promptly shut down internal and external networks and isolated its data center. With the help of external experts, it concluded the impact was limited to Japan. An emergency task force was formed under group crisis management and BCP guidelines, and network restoration and vulnerability assessments began. However, disruptions in accessing accounting data and the time required to establish alternative workflows meant that the financial reporting data needed for closing could not be obtained and verified on time, forcing a filing extension. This is the first instance where a cyberattack directly affected Asahi's financial reporting process. Ransomware cases in Japan are surging, with the Information-technology Promotion Agency (IPA) noting a roughly 50% increase in reported incidents in 2024.
Details of the Material Weakness in Internal Controls
Asahi assessed that it had a material weakness in the operation of its company-wide internal controls related to IT system policies. In its Japan operations, while regulations such as the Asahi Group Information System Management Rules and Information Security Rules set requirements for integrated security management and outlined compliance and technical measures to mitigate cyber risks, privilege management and other operational controls on part of its IT infrastructure were insufficient. This allowed the attacker to breach systems, severely affecting disclosure timeliness. Specifically, administrator privilege controls were weak, and password management and access controls were not implemented as mandated. Asahi stated that its internal controls over financial reporting were 'not effective' and filed its internal control report for fiscal 2025 with the Kanto Local Finance Bureau. It noted that remediation could not be completed by the fiscal year-end because containing the attack, restoring systems, and investigating the cause took priority. This weakness strikes at the core of the company's IT governance framework, inevitably undermining trust among investors and business partners. Asahi's market capitalization briefly fell following the disclosure, reflecting market concerns over governance.
Remediation and Future Preventive Measures
Asahi is advancing three key measures to address the weakness and prevent recurrence. First, to fix privilege management flaws, it is implementing stricter access controls and stronger passwords across all systems subject to internal control evaluation. Second, under the Information Security Committee, a continuous monitoring framework has been established to oversee operational compliance. Third, a Fit & Gap analysis is underway for critical information systems to identify differences between regulatory requirements and actual operations, with corrective actions being taken. Regular monitoring has already commenced to verify compliance and manage remediation progress. The company stated that all necessary adjustments have been reflected in its consolidated financial statements, and it received an unqualified opinion from its audit firm. While this confirms there are no material errors in the financials, restoring confidence in internal controls remains a task. Experts note that weak privilege management is a widespread vulnerability, and call for fundamental solutions such as adopting zero-trust architecture. Asahi plans a fundamental overhaul of its information security governance, including possible re-audits by external specialists.
Analyst take
The disclosure of this material weakness reveals lapses in Asahi's information security governance. In particular, poor privilege management points to missing basic safeguards. While cyberattacks may be unavoidable, the failure to maintain timely disclosure severely undermines investor trust. Even if the immediate market impact is modest, this will weigh on the company's long-term ESG standing. Vigilant oversight of Asahi's remediation efforts and the effectiveness of its preventive measures is needed. Publishing the findings of external expert reviews would boost transparency, and the market will be watching Asahi's commitment to disclosure.

