Regarding Personal Information That May Have Been Exposed Due to a Cyberattack
(Tokyo, Japan - July 17, 2026) Asahi Group Holdings, Ltd. has been conducting an investigation into the scope of information that was exposed, or may have been exposed, as a result of the cyberattack on systems used by the Asahi Group on September 29, 2025. On February 18, 2026, the Company announced the details and scope of the investigation completed as of that date. Following additional investigation and review, the Company has reassessed the scope of personal information that may have been exposed. The updated details are outlined below.
Regarding the cyberattack on September 29, 2025, the Company has taken the incident very seriously and promptly initiated investigations to determine the cause, identify the scope of impact, and consider measures to prevent recurrence. As a result of these investigations, it has been confirmed that an external attacker gained unauthorized access to the Asahi Group network through the network equipment located at our Group's site.
Investigations to date, including those conducted by external experts, have found no evidence that personal information stored on servers in our Group’s data center was transferred externally. However, taking into account discussions with the Personal Information Protection Commission and from the perspective of protecting the rights and interests of individuals, the Company has conducted a further review of the scope of potential exposure.
As a result, from the perspective of preventing secondary damage and in accordance with applicable laws and regulations, information for which the possibility of exposure cannot be completely ruled out will also be treated as falling within the scope of potential exposure. Accordingly, the affected parties, descriptions, and counts in “Personal information that may have been exposed (as of November 26, 2025)” announced on February 18, 2026, are revised as follows.
Personal information that may have been exposed (as of July 17, 2026)
| Affected parties | Description | Count (approx.) |
|---|---|---|
| Those who contacted the Customer Service Centers of Asahi Breweries, Ltd., Asahi Soft Drinks Co., Ltd., and Asahi Group Foods, Ltd. | Name, gender, address, phone number, email address | 1,525,000 |
| External contacts to whom we have sent congratulatory or condolence telegrams | Name, address, phone number | 117,000 |
| Employees (including retirees) | Name, date of birth, gender, address, phone number, email address, other | 107,000 |
| Family members of employees (including retirees) | Name, date of birth, gender | 162,000 |
| Directors and employees of business partners, as well as individual business partners and their employees, and others | Name, date of birth, gender, address, phone number, email address, other | 378,000 |
There are no changes to the details of the announcement “Personal information that has been exposed (as of February 18, 2026)” issued on February 18, 2026.
Those whose information may have been exposed are being notified in due course. As of the date of this announcement, no secondary damage, including unauthorized use of information, has been confirmed.