SHINDO3

JAXA

Unauthorized accessSize not disclosed

LEAK CONFIRMEDTrade secrets / Login ID / usernameClosed (final report)

Open in the live monitor ▶
Disclosed
Jul 5, 2024
Detected
Oct 2023
Detection to disclosure
278 days
Leak
Leak confirmed
Type
Unauthorized access
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced
Corporate number
9012405001241

What leaked

UnspecifiedPersonal information
Business dataInformation used in joint work with outside organizations
CredentialsAccount credentials (used to impersonate users on Microsoft 365)

Who is affected

  • JAXA officers and staff
  • People at outside organizations that work jointly with JAXA

Cause

A recently disclosed vulnerability in a VPN device was most likely exploited to break into some servers and endpoints. Account credentials stolen from them were used to access Microsoft 365 by impersonation. Several unknown malware samples were used, which made the intrusion hard to detect

Timeline

  1. Intrusion began
  2. Detected
  3. Contained
  4. JAXA published its findings (news reports began on November 29, 2023)

Response

  • Blocked the entry point
  • Forensic investigation
  • More monitoring
  • Governance / committee
  • Notified individuals

Cut off communication with the attacker and disconnected servers from the network, forensic investigation. Set up a vulnerability response process and stepped up monitoring of internal traffic logs. Long-term: stronger network monitoring, better external connection methods and stronger measures against impersonation. Individual apologies and notices to the people and organizations whose information leaked

What you should do

  1. Expect targeted phishing posing as HR or interview contacts
  2. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Passkeys or MFA for every account; monitor leaked credentials and rotate API keys
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources