SHINDO4

CASIO

Personal data8,478people

LEAK CONFIRMEDID document (type not stated) / HR / labour recordsRansomware · Closed (final report)

Open in the live monitor ▶
Disclosed
Oct 8, 2024
Detected
Oct 5, 2024
Detection to disclosure
3 days
Leak
Leak confirmed
Type
Ransomware
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced
Corporate number
4011001030015

What leaked

IdentityFull name, Gender (10 employees), Date of birth (10 employees)
Employment & HREmployee number, Department, Personnel information, Career history (job interview applicants)
ContactEmail address, Phone number, Company address, address and delivery address
ID documentsInformation shown on ID documents (10 employees, 2 business partners), Taxpayer number (former group company employees)
Family & private lifeFamily members' names, addresses, phone numbers, etc. (97 employees)
CredentialsHead office system account information (local group company employees)
Business dataCompany name
Transactions & activityPurchase date, product name, etc. (91 customers)
System & internalInvoices, contracts, sales data, meeting materials, internal review documents, etc.

Not leaked

  • The personal data confirmed leaked does not include credit card information

How many

  • People whose personal data was confirmed leaked (total) 8,478 people
  • Employees (Japan) 5,509 people
  • Local employees of group companies (Japan and overseas) 881 people
  • Former group company employees (overseas) 66 people
  • Business partners 1,922 people
  • Job interview applicants 9 people
  • Customers (delivery details, etc.) 91 people

Who is affected

  • Employees (including temporary and contract staff) and local employees of group companies
  • Family members of some employees
  • Former group company employees (overseas)
  • Business partners
  • Job interview applicants
  • Customers

Cause

On October 5, 2024 the company's servers were accessed from overseas and a ransomware attack made systems unusable. The company said its phishing email defences and its global network security, including overseas sites, were partly inadequate

Timeline

  1. Detected
  2. Reported to authority
  3. First disclosure
  4. Reported to authority
  5. Underground claimed the attack (claiming about 204.9 GB of stolen data)
  6. Ransomware attack and partial leak of personal and confidential information announced
  7. Reported to authority
  8. Investigation results: personal data of 8,478 people confirmed leaked

Response

  • Blocked the entry point
  • Forensic investigation
  • Notified individuals
  • Hotline
  • Governance / committee
  • Staff training

Restricted outside access, investigation with outside specialists, individual contact with affected people, a dedicated contact line, stronger IT security across the group, review of information management and more staff training

What you should do

  1. ID numbers can never be changed. Request your credit file from CIC, JICC and others and look for contracts or loans you didn't make
  2. Register a self-declaration (honnin shinkoku) with the credit bureaus so lenders check applications in your name more carefully. The stronger loan self-restriction scheme also blocks your own borrowing and can't be withdrawn for 3 months. Neither stops bank accounts being opened
  3. Don't open links in emails from this company. The apology email itself may be fake
  4. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  5. Watch for unexpected mail or invoices; your address is hard to change
  6. Expect targeted phishing posing as HR or interview contacts
  7. Check the company's notice to see if you're affected

Lessons for companies

  1. Offline backups with restore drills; segment the network
  2. Don't keep ID or bank data: delete after checks or use a KYC provider
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources