We take for granted the conveniences of the digital age: instant messaging, online shopping, the databases that power millions of businesses. Everything flows until something breaks and the routine stops. In companies, this failure can have devastating effects. This was confirmed by Jaguar Land Rover, which suffered a cyberattack that paralyzed its production lines. Now the scenario is repeating itself in Japan, where Asahi, the giant that controls about 40% of the beer market, has had to stop its activity and resort to the most basic: handwritten orders, paper documents, and faxes that ring again.
The incident broke out at the end of September when a ransomware attack left them inoperative. Asahi’s ordering and shipping systems in Japan were severely disrupted. In a few hours, the company had to suspend activity in most of its factories and completely reorganize its logistics. The country’s supermarkets and convenience chains, including 7-Eleven and FamilyMart, warned of possible stock shortages. Although production began to resume on a limited basis, the brewer admitted that it could not guarantee timelines for returning to normality.
When a Cyberattack Turns Off Screens and Forces You to Return to Paper
The systems that allow Asahi to process orders, coordinate deliveries, and communicate with distributors were out of service following the attack. Although factories could continue producing, the company was forced to stop activity because it could not manage a single shipping order. This measure was part of the containment protocol, which included blocking servers and suspending incoming mail from abroad. In mere hours, the largest brewer in the country transitioned from total automation to an almost complete stoppage.
Faced with the digital blockade, Asahi activated an emergency plan based on manual procedures. Orders were written down by hand, delivery notes were printed, and shipping confirmations were communicated via fax, much like in the past. The goal was simple: keep the product flowing, even if it was limited. This strategy partially reactivated the company’s distribution network, while they also prepared the reopening of their call center. Despite the slow and laborious response, it allowed the first batches of beer to leave the breweries once again.
Gradually, Asahi began to commission its factories. The six brewing centers returned to limited production, starting with the Asahi Super Dry line. Some soft drink and food plants were also reactivated but at a slower pace. The company specified that its production was still far from normal and that containment measures were still firmly in place.
The attack affected only Asahi’s domestic operations. The company clarified that its subsidiaries in Europe and the United Kingdom continued to operate without incidents. The Japanese segment, which contributes around 50% of its global income, was the only one hit. Although the geographic scope was limited, the economic and logistical implications within the country were notable.
A group named Qilin claimed responsibility for the cyber attack. This organization operates under a “ransomware as a service” model and has previously been involved in attacks against major corporations. Asahi has yet to confirm this version or detail the specific type of intrusion. Regardless, the Japanese Government is conducting an investigation to clarify the events.

Asahi is keeping its recovery plan active, focused on gradually restoring ordering and shipping systems. The immediate priority is to normalize production and fully reopen its customer service center. Starting in mid-October, the company hopes to increase the pace of distribution and recover part of the catalog affected by delays. A specific date for complete restoration has not yet been set, but the company assures that security measures will be reinforced before returning to full operation.
Images | Asahi (1, 2) | freepik
In Xataka | How often should we change ALL our passwords according to three cybersecurity experts

