ransomware
Blackfield Ransomware Demands $2M From Nidec Subsidiary
2026-06-30

Japanese motor giant Nidec is back in the ransomware news, this time thanks to a crew calling itself Blackfield. The gang is demanding $2 million to delete data it says it pulled from Nidec Chaun Choung Technology, the company's Taiwanese subsidiary.
Nidec confirmed the incident in a short statement. Ransomware damage was spotted on a server on 22 June 2026, affected systems were taken offline to stop it spreading, and the company acknowledged a possible information leak. So far, it says, nothing personal or confidential has been confirmed online. The impact on production and shipping at the subsidiary is still being worked out, and Nidec doesn't expect the wider group to feel it.
The pricing menu
The interesting bit is how Blackfield has structured its demand. It reads less like a ransom note and more like a service tier.
- $2 million and the stolen data quietly disappears.
- $400,000 and the data goes public, free for anyone to grab.
- $5,000 a day to extend the deadline, like the world's grimmest parking meter.
To back the threat up, the gang has posted file trees and sample documents on its leak site. The authenticity of any of it hasn't been independently confirmed.
Not Nidec's first visit to a leak site
What makes this story sting a little more is that Nidec has been here before. In October 2024, its Vietnamese arm, Nidec Precision, was hit and more than 50,000 files ended up exposed. That one got claimed twice over, by both 8Base and Everest, each running their own separate extortion attempt off the same breach. A useful reminder that once your data is loose, the number of people trying to monetise it isn't capped at one.
Nidec is a $17 billion manufacturer with operations in more than 40 countries. At that scale, the attack surface is enormous and the org chart is full of subsidiaries that each have their own IT estates, their own vendors, and their own staff clicking on their own emails. Headquarters can have the tightest controls in the industry and still get a phone call about a subsidiary three time zones away that didn't.
The pattern worth noticing
Two breaches in under two years, both at subsidiaries, neither at the parent. That's not a coincidence so much as the maths of large multinationals. Ransomware crews follow the path of least resistance, and the path of least resistance through a 40-country conglomerate runs through whichever local office has the oldest server, the least training, or the most overworked admin.
Blackfield's tiered pricing is also worth a moment. Treating extortion like a SaaS pricing page is darkly on-brand for where ransomware has ended up: professionalised, productised, and entirely uninterested in whether the victim is having a good quarter. The $5,000-a-day clock is a small detail, but it tells you everything about how these crews think. Every hour of indecision has a line item.
Whether Nidec pays, negotiates, or sits tight, the file trees are already out there. The next move belongs to Blackfield, and the parking meter is running.