SHINDO5
KADOKAWA / Dwango (niconico)
KADOKAWA CORPORATION
nicovideo.jp
Personal data254,241people
LEAK CONFIRMEDBank account / Date of birthRansomware · Closed (final report)
Open in the live monitor ▶- Disclosed
- Jun 9, 2024
- Detected
- Jun 8, 2024 03:30 JST
- Detection to disclosure
- 1 day
- Leak
- Leak confirmed
- Type
- Ransomware
- Status
- Closed (final report)
- Security spend
- Not checked yet
- Compensation
- Not announced
- Corporate number
- 2010001163289
What leaked
IdentityFull name, Date of birth, Professional or stage name
ContactAddress, Phone number, Email address
Financial & paymentBank account information
Account dataAttributes such as education history, Student information such as enrolment year, homeroom teacher and next school
Employment & HREmployee number, Department, Personnel information such as attendance records
Transactions & activitySome contracts with business partners and affiliated companies
System & internalInternal documents, including legal documents
Not leaked
- No leak from Dwango has been confirmed for niconico users' account information (login email address and password) or credit card information
- No leak from Dwango has been confirmed for niconico users' account information (login email address and password) or credit card information
- No leak from Dwango has been confirmed for niconico users' account information (login email address and password) or credit card information
How many
- People whose personal data was confirmed leaked (total) 254,241 people
Who is affected
- Business partners (including creators and sole proprietors)
- Some current and former students, guardians, applicants and material requesters of N Junior High, N High School and S High School
- Some former staff of Kadokawa Dwango Gakuen
- All employees (including contract, temporary and part-time staff)
Cause
The root cause is believed to be employee account credentials stolen through phishing or similar attacks. The attacker used the stolen accounts to move through the internal network and encrypted servers with ransomware
Timeline
- Detected
- Service suspended
- First disclosure
- Reported to authority
- Report No. 3 published
- BlackSuit listed KADOKAWA on its leak site, claiming about 1.5 TB of stolen data and threatening to publish it on July 1
- Investigation results: external leak of personal data of 254,241 people confirmed
- Service restored
Response
- Service stopped
- Forensic investigation
- Notified individuals
- Hotline
Shut down servers and suspended services, set up a response headquarters, investigation with outside specialists, individual apologies and notices to people whose data was confirmed leaked, dedicated contact desks for each group. Preparing legal action, including criminal complaints, against people spreading the leaked data
What you should do
- Scammers who know your account number pose as refund staff. No bank or company asks for your PIN
- Don't open links in emails from this company. The apology email itself may be fake
- Treat refund or apology calls and texts as scams. Call back only on the number from the official site
- Watch for unexpected mail or invoices; your address is hard to change
- Expect targeted phishing posing as HR or interview contacts
- Check the company's notice to see if you're affected
Lessons for companies
- Passkeys or MFA for every account; monitor leaked credentials and rotate API keys
- Offline backups with restore drills; segment the network
- Don't keep ID or bank data: delete after checks or use a KYC provider
- Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
- Run red teaming and AI-assisted hardening, and publish how much you invest
Sources
- KADOKAWA, Dwango and Kadokawa Dwango Gakuen Official notice · Aug 5, 2024
- piyolog Researcher · Aug 19, 2024
- ITmedia NEWS News · Jun 28, 2024
- KAI-YOU News · Jun 27, 2024
- gBizINFO Registry