Local Chorus
Local news from local sources, read in your language.
Developing

Daiwa Securities: vendor breach may have exposed data of 110,000 customers

🇯🇵 Japan, Tokyo 10:10 IT & software Business7 Tech4 Official Community2 updated 2 h ago first reported by 日テレNEWS

Version 2: Later reporting added that Daiwa Securities had begun identifying affected customers and contacting them individually, and one tech outlet's headline said the vendor's breach extended beyond Daiwa; the record counts and the company's other statements were unchanged.

In short

Daiwa Securities said on Oct 5 that a server at outsourcing vendor Scalar Communications was subject to unauthorized access and that about 220,000 records may have leaked, including names, email addresses and securities account numbers for about 110,000 customers. The company said its own systems were not confirmed to have been breached, that no unauthorized trades had been found, and that the leaked information alone cannot be used to access securities accounts or trade. Daiwa has begun contacting affected customers individually and warned about phishing calls and emails.

Read the full story 2 min read

Daiwa Securities said on Oct 5 that a server at outsourcing vendor Scalar Communications had been subject to unauthorized access and that customer information stored on it may have been improperly obtained. About 110,000 customers' names, email addresses and securities account numbers may be affected; including inquiry information that does not identify individuals, the total could reach about 220,000 records, the company said. Daiwa Securities Group headquarters announced the same figures. NHK News reported the company as saying that no unauthorized transactions had been confirmed at that point. [ 1 , 2 , 3 , 5 , 6 , 7 , 9 ]

The unauthorized access occurred between about 20:33 on Oct 2 and 08:01 on Oct 3, according to the company and the vendor. Scalar Communications, based in Shibuya, Tokyo, provides the service Daiwa uses to manage inquiries received over the internet, and its server held records of inquiries already accepted, including Daiwa customer data. ITmedia reported that, according to Scalar, Daiwa was notified on Oct 3; emergency security measures had been implemented and no further unauthorized access or leaks had been confirmed at that time. [ 1 , 3 , 8 , 10 ]

Daiwa said no unauthorized access to its own systems had been confirmed. It said the information that may have leaked cannot by itself be used to access securities accounts or to carry out transactions, including online trading. As of Oct 5, it said it had found no unauthorized trades and no evidence that the information had been published or spread online. [ 1 , 2 , 3 , 6 , 9 , 10 , 26 ]

Daiwa plans to contact affected customers individually, and TBS NEWS DIG reported that it had begun identifying customers and individual notification. The brokerage warned that names and inquiry details could be misused in scam calls or emails posing as Daiwa, and asked customers not to open links or attachments in suspicious messages or to disclose passwords, PINs or one-time passwords. ITmedia reported that Daiwa is checking its contractors and will decide on strengthened contractor-management measures and their timing after confirming Scalar's cause investigation and countermeasures, and that it will promptly disclose any new facts. [ 1 , 3 , 10 , 14 ]

Nikkei reported that the disclosure moved the market. Daiwa Securities Group shares (code 8601) on the Prime market stood at 1,725.50 yen at 13:45 on Oct 5, down 25.50 yen, or 1.45%, from the end of the previous week, with selling by investors waiting to see how the situation develops. The Nikkei average briefly topped 70,000, while Nomura (8604) and others remained firm in the afternoon, Nikkei reported. [ 7 ]

Why it matters

The incident exposes Daiwa Securities to risk through an outside contractor rather than its own systems, and the documents show it drew investor attention: Nikkei reported the group's shares fell in afternoon trading on Oct 5. Daiwa has said it will review how it manages contractors once Scalar Communications completes its investigation, so the immediate consequences are customer-notification and phishing-warning efforts rather than any confirmed misuse of the data.

Key facts

  • Daiwa Securities announced on Oct 5 that a server at outsourcing vendor Scalar Communications was subject to unauthorized access and that customer information may have been improperly obtained. [ 1 , 2 , 5 , 6 , 7 , 8 , 9 , 10 , 26 ]
  • The unauthorized access occurred between about 20:33 on Oct 2 and 08:01 on Oct 3. [ 1 , 3 , 8 , 10 ]
  • About 220,000 records may have leaked, of which about 110,000 include personal information such as names, email addresses and securities account numbers. [ 1 , 2 , 4 , 6 , 8 , 9 , 10 , 14 , 17 , 26 ]
  • Daiwa said no unauthorized access to its own systems had been confirmed. [ 1 , 3 , 10 , 26 ]
  • Daiwa said the information that may have leaked cannot by itself be used to access securities accounts or to trade, including online trading. [ 1 , 2 , 3 , 6 , 9 , 10 , 26 ]
  • As of Oct 5, Daiwa said no unauthorized trades and no public posting or spread of the information online had been confirmed. [ 1 , 2 , 3 , 5 , 6 , 9 , 10 , 14 , 17 ]
  • Daiwa has begun identifying affected customers and contacting them individually, and warned customers about scam calls and emails misusing names and inquiry details. [ 1 , 3 , 10 , 14 ]
  • Nikkei reported Daiwa Securities Group shares (code 8601) stood at 1,725.50 yen at 13:45 on Oct 5, down 25.50 yen, or 1.45%, from the end of the previous week. [ 7 ]

Confirmed by several sources

  • Daiwa Securities announced on Oct 5 that a server at outsourcing vendor Scalar Communications was subject to unauthorized access and that customer information may have been improperly obtained. [ 1 , 2 , 5 , 6 , 7 , 8 , 9 , 10 , 26 ]
  • The unauthorized access occurred between about 20:33 on Oct 2 and 08:01 on Oct 3. [ 1 , 3 , 8 , 10 ]
  • About 220,000 records may have leaked, including about 110,000 containing personal information such as names, email addresses and securities account numbers. [ 1 , 2 , 4 , 6 , 8 , 9 , 10 , 14 , 17 , 26 ]
  • Daiwa said no unauthorized access to its own systems had been confirmed, and that the leaked information alone cannot be used to access securities accounts or make trades. [ 1 , 2 , 3 , 6 , 9 , 10 , 26 ]
  • Daiwa said no unauthorized trades and no public posting or spread of the information online had been confirmed as of Oct 5. [ 1 , 2 , 3 , 5 , 6 , 9 , 10 , 14 , 17 ]
  • NHK News, an official outlet, reported that personal information of about 110,000 customers may have leaked and that no improper transactions had been confirmed. [ 5 ]

Still unclear

  • Whether the information was actually taken or only may have been taken. The documents describe a possible leak and say no misuse has been confirmed, but do not state that exfiltration has been ruled out.
  • Who carried out the unauthorized access and how. No document identifies an attacker, a method or a motive.
  • The exact number of people affected. Outlets cite about 220,000 records including non-identifying inquiry information and about 110,000 items of personal information, without giving a confirmed number of individuals.
  • Whether other companies were also affected through the same vendor. Nikkei xTECH's headline quotes the phrase “被害は当社以外も” (damage beyond our company as well), but the article text does not say which other clients were affected.
  • When Daiwa Securities learned of the incident. Only ITmedia reports that the company was notified on Oct 3; other outlets do not give a notification date.
  • When strengthened contractor-management measures will be decided. Only ITmedia reports that Daiwa will set the measures and their timing after confirming Scalar Communications' cause investigation and countermeasures, with no date given.

What local media are saying

Business mediaBusiness outlets led with the scale of the possible leak — about 220,000 records overall and about 110,000 items of personal information — and repeated Daiwa's statement that the data cannot be used for transactions; Nikkei reported the group's share price decline, and TBS NEWS DIG later reported that Daiwa had begun identifying affected customers and contacting them individually. [ 4 , 6 , 7 , 8 , 9 , 12 , 14 , 17 ]
Technology mediaTech outlets carried the most operational detail: the vendor Scalar Communications and its Shibuya, Tokyo location, the Oct 2–3 intrusion window, the Oct 3 notification to Daiwa, emergency security measures, and Daiwa's plan to review contractor management; Nikkei xTECH's headline also said the vendor's damage extends beyond Daiwa Securities. [ 1 , 10 , 26 ]
Official sourcesNHK News, an official outlet, reported that personal information of about 110,000 customers, including names and account numbers, may have leaked and that no improper transactions had been confirmed. [ 5 ]
Community and socialCommunity aggregators repeated the announcement, emphasising the roughly 220,000 records and Daiwa's explanation that transactions, including online, are impossible with the leaked information. [ 2 , 3 ]

Timeline, local time

  1. Unauthorized access to Scalar Communications' server begins, according to Daiwa Securities and Scalar Communications. [ 1 , 3 , 8 , 10 ]
  2. The unauthorized access ends. [ 1 , 3 , 8 , 10 ]
  3. Daiwa Securities announces that customer information may have leaked, according to Nikkei. [ 7 ]
  4. Daiwa Securities Group shares (code 8601) stand at 1,725.50 yen on the Prime market, down 25.50 yen or 1.45% from the end of the previous week, Nikkei reports. [ 7 ]
  5. TBS NEWS DIG reports that Daiwa has begun identifying affected customers and individual notification, with no unauthorized trades confirmed. [ 14 ]
  6. Nikkei xTECH reports the disclosure, saying in its headline that damage at the vendor extends beyond Daiwa Securities. [ 26 ]