SHINDO5

ISETO

ID documents13,150peopleof 3.1M people affected in total

LEAK CONFIRMEDRansomware · Closed (final report)

Open in the live monitor ▶
Disclosed
May 29, 2024
Detected
May 26, 2024
Detection to disclosure
3 days
Leak
Leak confirmed
Type
Ransomware
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced
Corporate number
4130001019931

What leaked

UnspecifiedPersonal data of clients' customers (including sensitive personal information)

How many

  • People whose personal data was affected (total) 3.1M people
  • Of these, from private sector clients 2.5M people
  • Of these, from government clients 566,561 people
  • People whose data included sensitive personal information 13,150 people
  • Client organizations (32 private sector, 9 government) 41 organizations

Who is affected

  • Customers of client companies (private sector)
  • People in data entrusted by government bodies

Cause

The attacker entered the core network through a VPN device and encrypted PCs and servers at the information processing center and sales offices nationwide with ransomware. The VPN device had not been updated since April 2021 and a vulnerability was left unaddressed. The core network administrator account had used the same 11-character, lowercase-only password since February 2017. Client data was kept for convenience on servers not meant to handle it and was not deleted after the work ended

Timeline

  1. Intrusion began
  2. Detected
  3. First disclosure
  4. 8base listed the company on its leak site
  5. Posted on leak site
  6. Announced that the leaked data included personal data of clients' customers
  7. Investigation results, cause and prevention measures announced

Response

  • Blocked the entry point
  • Forensic investigation
  • Governance / committee
  • Staff training

Set up a company-wide response headquarters and an investigation with outside specialists. Retired the VPN, strengthened authentication, banned moving data outside controlled areas, clarified data storage rules, tightened audits and trained employees in security

What you should do

  1. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Data outlived the contract. Always get proof of deletion and set retention limits
  3. Offline backups with restore drills; segment the network
  4. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  5. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources