technology 6 min read

Why a 50-Year-Old VPN Was the Weak Link in Paru Group's Attack

When Paru Group's legacy maintenance VPN fell to ransomware, it cascaded through Active Directory and knocked out 100 servers. The recovery—completed in just 50 days with an AWS pivot—reveals the hidden fragility of aging Japanese enterprise infrastructure and what it means for global IT resilience.

  • Cybersecurity
  • Ransomware
  • Japan IT
  • Legacy Infrastructure
  • AWS Migration
  • Business Continuity

The attack vector nobody was watching

On June 16, 2024, about 100 servers at Paru Group went dark simultaneously. Email stopped. The sales management system crashed. Point-of-sale terminals in hundreds of stores lost connection to headquarters. The company could no longer place orders or move inventory. For a retail group that operates brands like 3COINS, CIAOPANIC, and un dix cors across roughly 1,000 stores, this was not a disruption—it was a shutdown.

What made the incident notable was not the scale of the damage but the entry point. Forensic investigation revealed the attackers did not breach the core business systems first. They came through a remote VPN dedicated to maintenance—a system that had grown old and unmonitored. From there, they moved to an aging attendance management server, and from that server they compromised the Active Directory domain controller. Once AD fell, every device under its control was accessible. The entire data center came down with it.

This sequence tells a story that repeats across Japanese enterprise IT and one that English-language coverage rarely frames clearly: the attack did not target the crown jewels. It targeted the infrastructure no one thought needed protecting because it was not part of the business layer.

Who owns the gap between old systems and new threats

Paru Group is a holding company for apparel and general merchandise, managing around 50 brands. Its IT architecture before the attack followed a pattern common among mid-to-large Japanese corporations: a centralized data center housing roughly 100 physical servers, all connected through legacy remote access tools that predated modern zero-trust thinking. The maintenance VPN, the attendance system, the Active Directory infrastructure—they were older than the cloud strategies the company had begun discussing quietly.

The consequence of that age gap was not merely technical. It was organizational. Security decisions about those systems had been deferred for years. The VPN was still in use because nobody had built a replacement. The attendance server was still on-premise because migration had never been prioritized. When attackers found that path, they found a corridor that had been left unlocked.

Paru Group’s守山宗行, leader of the IT coordination division, described the aftermath as a period of near-silence in headquarters and a flood of emergency calls from stores. The company had to make immediate decisions under extreme uncertainty. The first was to sever internet connectivity entirely, which stopped the spread but also stopped operations. The second was to rebuild connectivity for stores without re-exposing the compromised network.

The workaround that kept stores open

Paru Group’s incident response revealed a practical truth about retail IT: headquarters can fall and the store floor must still operate. The company had already separated its e-commerce platform, PAL CLOSET, and its social media infrastructure from the main network—a decision that may have been made for performance reasons rather than security ones, but which proved decisive. Those systems survived untouched.

For the remaining 1,000 stores, the company distributed roughly 900 pocket Wi-Fi units. Headquarters replaced infected PCs and used the isolated SNS circuit to restore internet access. This was not a recovery strategy. It was triage. But it bought the time needed to execute one.

The 50-day pivot to the cloud

The most striking element of Paru Group’s response was not the initial containment but the speed of the rebuild. Three options were evaluated: rebuilding in a separate environment within the existing data center, contracting a new facility with TOKAI Communications, or migrating to AWS.

Cloud adoption had previously faced resistance from executives who preferred on-premise control. The attack changed that calculus almost instantly. AWS migration was approved, and the target was set for end of September 2024.

Then an additional constraint appeared. Paru Group was acquiring the women’s apparel brand w closet, with the transaction closing at the end of August. The sales management system needed to be operational before the acquisition could proceed smoothly. The deadline moved up. The project compressed from what would have been a year-long transformation into a 50-day sprint.

The AWS migration was completed by August 5. The w closet acquisition followed at the end of the month without delay. TOKAI Communications provided the integration support that made the schedule feasible—a firm that operates one of Japan’s largest private MPLS networks with roughly 2,300 closed-network lines connecting to AWS, according to its representatives.

What the new architecture looks like

The post-attack infrastructure is notably simpler than the pre-attack version. The old narrow private network was replaced with TOKAI Communications’ BroadLine carrier service, and the connection to AWS was rebuilt using AWS Direct Connect with redundancy. The SD-WAN rollout across approximately 1,000 store locations was completed in roughly one week, replacing the older IP-VPN topology.

Security controls were substantially strengthened. Internet traffic was consolidated through a unified UTM device with all logs feeding into a SIEM platform. Authentication shifted from AD login alone to certificate-based authentication with multi-factor authentication added. Amazon GuardDuty and AWS Security Hub were deployed alongside EDR agents on every EC2 instance.

The disaster recovery exercise conducted after restoration demonstrated the scale of improvement: a process that previously required about two months to recover was completed in approximately six hours.

Why this matters beyond Japan

Paru Group’s experience is not an outlier. It is a template. The pattern—legacy VPN, aging server, AD compromise, cascading failure—is increasingly common as enterprises delay infrastructure refresh cycles while cyber threats evolve faster than procurement processes. What distinguishes the Paru Group case is the speed and clarity of the response, and the willingness to use a crisis as leverage for a migration that was already planned but stalled.

The broader signal is that organizations should stop treating old internal systems as low-risk. The maintenance VPN is not benign infrastructure. It is often the weakest point in the network because it was designed for convenience, not defense, and it is frequently forgotten until it is exploited.

Paru Group’s守山 stated that the company now operates on the assumption that 100 percent prevention is impossible. The strategy has shifted toward early detection and damage limitation. That is a realistic posture for an industry that has spent decades building security walls around the wrong things.

What happens next

Paru Group will continue weekly operations reviews with TOKAI Communications and is expected to expand AWS capabilities beyond the initial recovery scope. The DR testing results suggest the company now has a credible fallback position that did not exist before the attack.

For the wider enterprise IT community, the lesson is concrete: review your legacy access paths this quarter. The VPN you inherited from a previous vendor, the attendance system running on a server nobody can date, the AD forest that has grown unmanaged—they are not background noise. They are the most likely entry point for the next incident.

Paru Group survived because it acted fast and because it had at least one system—PAL CLOSET—that was isolated from the rest. The companies that do not have that luck will learn the same lesson in a harder way.