ISETO
ISETO CORPORATION
ID documents13,150peopleof 3.1M people affected in total
LEAK CONFIRMEDRansomware · Closed (final report)
Open in the live monitor ▶- Disclosed
- May 29, 2024
- Detected
- May 26, 2024
- Detection to disclosure
- 3 days
- Leak
- Leak confirmed
- Type
- Ransomware
- Status
- Closed (final report)
- Security spend
- Not checked yet
- Compensation
- Not announced
- Corporate number
- 4130001019931
What leaked
How many
- People whose personal data was affected (total) 3.1M people
- Of these, from private sector clients 2.5M people
- Of these, from government clients 566,561 people
- People whose data included sensitive personal information 13,150 people
- Client organizations (32 private sector, 9 government) 41 organizations
Who is affected
- Customers of client companies (private sector)
- People in data entrusted by government bodies
Cause
The attacker entered the core network through a VPN device and encrypted PCs and servers at the information processing center and sales offices nationwide with ransomware. The VPN device had not been updated since April 2021 and a vulnerability was left unaddressed. The core network administrator account had used the same 11-character, lowercase-only password since February 2017. Client data was kept for convenience on servers not meant to handle it and was not deleted after the work ended
Timeline
- Intrusion began
- Detected
- First disclosure
- 8base listed the company on its leak site
- Posted on leak site
- Announced that the leaked data included personal data of clients' customers
- Investigation results, cause and prevention measures announced
Response
- Blocked the entry point
- Forensic investigation
- Governance / committee
- Staff training
Set up a company-wide response headquarters and an investigation with outside specialists. Retired the VPN, strengthened authentication, banned moving data outside controlled areas, clarified data storage rules, tightened audits and trained employees in security
What you should do
- Check the company's notice to see if you're affected
Lessons for companies
- Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
- Data outlived the contract. Always get proof of deletion and set retention limits
- Offline backups with restore drills; segment the network
- Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
- Run red teaming and AI-assisted hardening, and publish how much you invest
Sources
- ISETO (first report) Official notice · May 29, 2024
- ISETO (investigation results) Official notice · Oct 4, 2024
- Personal Information Protection Commission Regulator · Mar 19, 2025
- piyolog Researcher · Jun 15, 2024
- gBizINFO Registry