Local Chorus
Local news from local sources, read in your language.
Contested

Daiwa Securities and Osaka university report cyberattacks; data may have leaked

🇯🇵 Japan, Tokyo 07:57 IT & software Business3 Tech Community updated 6 h ago first reported by 読売新聞

In short

Daiwa Securities said a contractor’s server was illegally accessed and information on about 110,000 customers may have leaked, while Osaka Metropolitan University said a ransomware attack is the suspected cause of a system failure that was still continuing. Other Japanese companies, including Monogatari Corporation and the car-sharing service Times Car, also reported data leaks, and a researcher quoted by Livedoor News said the purpose of the attacks is unclear.

Read the full story 3 min read

Daiwa Securities said on Oct 5 that a server at an outsourcing contractor had been illegally accessed and that about 220,000 items of information, including personal data such as names, email addresses and account numbers for roughly 110,000 customers, may have leaked, according to Yomiuri Shimbun. The contractor, Scala Communications of Tokyo, which handles internet inquiries for the brokerage, was illegally accessed on Oct 2 and 3, the company said. Daiwa said no secondary damage such as fraudulent transactions had been confirmed, and that the information cannot be used to access securities accounts or to trade. [ 1 , 2 ]

Osaka Metropolitan University said on Oct 5 that a ransomware attack is the suspected cause of a large-scale system failure found early on Oct 2, and that the failure was still affecting most of its systems with no estimate for recovery. The university said data had been tampered with and that personal information on more than 130,000 students, alumni and staff — names, addresses and photographs on student ID cards, as well as bank account details used for staff salary transfers — may have leaked. It said it was consulting Osaka prefectural police and had reported the matter to the national personal information protection commission. [ 1 ]

Other companies reported breaches in the same period. Monogatari Corporation, which operates the Yakiniku King restaurant chain, said on Oct 5 that its app member management system had been illegally accessed and that about 10.8 million records of personal information such as names, phone numbers and email addresses had leaked, with no credit card data included. The car-sharing service Times Car reported that about 1.6 million identity documents, including driver’s licence images, had leaked, and a website set up for a class action drew more than 37,000 registrations in six days as of 9:00 on Oct 5. Nikkei said on Oct 4 that employee accounts had been attacked and about 9,000 emails impersonating staff were sent to internal and business contacts. The programme It! counted 11 cyber incidents between Sept 25 and Oct 4, including at Keio Electric Railway, Tokyo Metro, Yamato Transport and Sagawa Express. [ 2 ]

A researcher at the security research centre of the company Macnica told Livedoor News that this wave of attacks was short in duration and broad in scope, so AI may be carrying out the work, and that unlike earlier ransomware attacks that demanded money, the purpose is unclear. He said attacks of this scale have not occurred overseas and Japan may be the target, adding that attackers are adopting AI faster than corporate defences are improving. Members of the public interviewed by Livedoor News described suspected fraud calls and card misuse. [ 2 ]

Mynavi News published an analysis piece that did not report the specific incidents, arguing that cybersecurity is now a geopolitical and economic-security issue: attacks cross borders easily, states may target critical infrastructure, and companies depend on supply chains and digital services that can become entry points. It added that not every attack is tied to state rivalry, with ransomware by criminal groups remaining common. [ 3 ]

Why it matters

The reported breaches hit companies in finance, food service, car sharing, transport and logistics, and a university, touching services used in daily life. A researcher quoted by Livedoor News said attackers appear to be using AI and that Japan may be the target, which bears on how Japanese organisations and their contractors handle customer data. Osaka Metropolitan University said the failure was still affecting most of its systems with no recovery estimate.

Key facts

  • Daiwa Securities said on Oct 5 that an outsourcing contractor’s server was illegally accessed and about 220,000 items of information, including personal data such as names, email addresses and account numbers for roughly 110,000 customers, may have leaked. [ 1 ]
  • Daiwa said no secondary damage such as unauthorised transactions had been confirmed, and that the possibly leaked data cannot be used to access securities accounts or to trade. [ 1 ]
  • The contractor, Scala Communications of Tokyo, was illegally accessed on Oct 2 and 3, according to Daiwa. [ 1 ]
  • Osaka Metropolitan University said on Oct 5 that a ransomware attack is the suspected cause of a system failure found early on Oct 2, which was still affecting most of its systems, and that data on more than 130,000 students, alumni and staff may have leaked. [ 1 ]
  • Monogatari Corporation, which operates Yakiniku King, said on Oct 5 that its app member management system was illegally accessed and about 10.8 million records of personal information leaked, with no credit card data included. [ 2 ]
  • Times Car reported that about 1.6 million identity documents, including driver’s licence images, leaked, and a website for a class action drew more than 37,000 registrations in six days as of 9:00 on Oct 5. [ 2 ]
  • A researcher at Macnica’s security research centre told Livedoor News the attacks may be carried out with AI, that their purpose is unclear, and that Japan may be the target. [ 2 ]
  • The programme It! counted 11 cyber incidents between Sept 25 and Oct 4, including at Keio Electric Railway, Tokyo Metro, Yamato Transport and Sagawa Express. [ 2 ]

Confirmed by several sources

  • Nothing is confirmed by two independent outlets yet.

Still unclear

  • Who carried out the attacks and for what purpose. No document states an attacker or motive; Livedoor News quotes a researcher saying the purpose is unclear and that Japan may be targeted.
  • Whether personal data actually leaked in each case. Daiwa describes only a possible leak, and the university says it is investigating the possibility of a leak and has reported to the national personal information protection commission.
  • Whether the incidents are connected. The documents describe the cases separately and do not say they are linked.
  • The full scale of the wave of attacks. The figure of 11 incidents between Sept 25 and Oct 4 comes from one broadcaster’s count reported by Livedoor News alone.
  • Daiwa Securities reported that a contractor’s data breach may have exposed information on about 110,000 customers, a figure carried by both Yomiuri Shimbun and Livedoor News. Reported by a single source so far

What local media are saying

Business mediaYomiuri Shimbun reported Daiwa Securities’ announcement in detail, including the number of records, the customer count and the contractor involved, and set out Osaka Metropolitan University’s ransomware suspicion, the affected data and its filings with police and the personal information commission. [ 1 ]
Community and socialLivedoor News assembled a series of incidents at transport, logistics, food-service and car-sharing companies, added interviews with members of the public about suspected fraud calls and leaked data, and quoted an expert saying AI may be driving the attacks and that their purpose is unclear. [ 2 ]
Technology mediaMynavi News published an analysis piece framing cybersecurity as a geopolitical and economic-security issue — cross-border attacks, critical infrastructure, supply chains — and did not report the specific incidents. [ 3 ]

Timeline, local time

  1. Osaka Metropolitan University’s system failure is identified and data tampering is found. [ 1 ]
  2. Scala Communications, a Tokyo contractor used by Daiwa Securities, is illegally accessed. [ 1 ]
  3. Nikkei says employee accounts were attacked and about 9,000 emails impersonating staff were sent. [ 2 ]
  4. Registrations on a site for a class action over the Times Car leak reach more than 37,000 within six days of its launch. [ 2 ]
  5. Daiwa Securities, Osaka Metropolitan University and Monogatari Corporation announce breaches and possible data leaks. [ 1 , 2 ]
  6. Yomiuri Shimbun, Livedoor News and Mynavi News publish reports on the attacks. [ 1 , 2 , 3 ]