SHINDO5

KADOKAWA / Dwango (niconico)

nicovideo.jp

Personal data254,241people

LEAK CONFIRMEDBank account / Date of birthRansomware · Closed (final report)

Open in the live monitor ▶
Disclosed
Jun 9, 2024
Detected
Jun 8, 2024 03:30 JST
Detection to disclosure
1 day
Leak
Leak confirmed
Type
Ransomware
Status
Closed (final report)
Security spend
Not checked yet
Compensation
Not announced
Corporate number
2010001163289

What leaked

IdentityFull name, Date of birth, Professional or stage name
ContactAddress, Phone number, Email address
Financial & paymentBank account information
Account dataAttributes such as education history, Student information such as enrolment year, homeroom teacher and next school
Employment & HREmployee number, Department, Personnel information such as attendance records
Transactions & activitySome contracts with business partners and affiliated companies
System & internalInternal documents, including legal documents

Not leaked

  • No leak from Dwango has been confirmed for niconico users' account information (login email address and password) or credit card information
  • No leak from Dwango has been confirmed for niconico users' account information (login email address and password) or credit card information
  • No leak from Dwango has been confirmed for niconico users' account information (login email address and password) or credit card information

How many

  • People whose personal data was confirmed leaked (total) 254,241 people

Who is affected

  • Business partners (including creators and sole proprietors)
  • Some current and former students, guardians, applicants and material requesters of N Junior High, N High School and S High School
  • Some former staff of Kadokawa Dwango Gakuen
  • All employees (including contract, temporary and part-time staff)

Cause

The root cause is believed to be employee account credentials stolen through phishing or similar attacks. The attacker used the stolen accounts to move through the internal network and encrypted servers with ransomware

Timeline

  1. Detected
  2. Service suspended
  3. First disclosure
  4. Reported to authority
  5. Report No. 3 published
  6. BlackSuit listed KADOKAWA on its leak site, claiming about 1.5 TB of stolen data and threatening to publish it on July 1
  7. Investigation results: external leak of personal data of 254,241 people confirmed
  8. Service restored

Response

  • Service stopped
  • Forensic investigation
  • Notified individuals
  • Hotline

Shut down servers and suspended services, set up a response headquarters, investigation with outside specialists, individual apologies and notices to people whose data was confirmed leaked, dedicated contact desks for each group. Preparing legal action, including criminal complaints, against people spreading the leaked data

What you should do

  1. Scammers who know your account number pose as refund staff. No bank or company asks for your PIN
  2. Don't open links in emails from this company. The apology email itself may be fake
  3. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  4. Watch for unexpected mail or invoices; your address is hard to change
  5. Expect targeted phishing posing as HR or interview contacts
  6. Check the company's notice to see if you're affected

Lessons for companies

  1. Passkeys or MFA for every account; monitor leaked credentials and rotate API keys
  2. Offline backups with restore drills; segment the network
  3. Don't keep ID or bank data: delete after checks or use a KYC provider
  4. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  5. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources