RANSOMWARE VICTIM

Japan Exchange Group

root📅 November 28, 2025
8
same group

Attack Intelligence

Japan Exchange Group was compromised in a ransomware attack attributed to root in November 2025. The organization, operating in an undisclosed sector in Unknown, was added to the group's data leak site as part of an extortion campaign.

root operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

Japan Exchange Group, Inc. a holding company which engages in the operation of financial instruments exchange. It provides market infrastructure for financial instruments including financial instrument exchanges. It also offers investors a venue to manage their financial assets and listed companies a platform to raise the funds. The company was founded on April 1, 1949 and is headquartered in Tokyo, Japan.

Other Victims — root (8)

Quick Facts

Attack DateNov 28, 2025
Intel Sourceransomlook

Threat Group

root
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.