Sompo Japan says about 60,000 customer records may have leaked after vendor breach
In short
Sompo Japan said on October 7 that a subcontractor's server used to handle inquiries for its business-oriented dashcam service “SMILING ROAD” was hit by unauthorized access, and about 60,000 customer records may have leaked. The data may include names, phone numbers, addresses, employer details and inquiry content, but not bank account, credit card or My Number information. The vendor, Scala Communications, says the same server may have exposed up to 713,126 records from as many as five companies; Daiwa Securities and Citizen Watch have also disclosed possible leaks.
Read the full story 2 min read
Sompo Japan said on October 7 that a server operated by an outside subcontractor had been subject to unauthorized access, and that about 60,000 customer records may have leaked. The server was used to handle inquiries about “SMILING ROAD”, a communication-enabled dashcam service the insurer provides to businesses, according to the company's announcement. [ 1 , 2 , 3 , 4 , 5 , 6 , 7 , 8 ]
The records that may have leaked include names, phone numbers, addresses and email addresses, along with employer information such as company and department names. According to the announcement, they also include driver-identifying IDs, the type and date of driving alerts, dashcam serial numbers, application numbers and the subject and text of inquiries. Sompo Japan says bank account, credit card and My Number card information is not included. The roughly 60,000 figure counts multiple inquiries by the same person more than once. [ 2 , 8 ]
The vendor is Scala Communications, based in Shibuya, Tokyo, which provides the FAQ system “i-ask”. Scala Communications said a third party logged into the i-ask administration site from around 20:33 on October 2 to around 08:01 on October 3 and installed a malicious program. It said inquiry data from up to five companies running on the same server, or up to 713,126 records, may have leaked. Sompo Japan said it has not confirmed any unauthorized access to its own systems. [ 2 ]
Other companies using the same vendor have also disclosed possible leaks. Daiwa Securities announced on October 5 that customer information may have leaked; Nippon TV News put the figure at 110,000 customers, while ITmedia reported about 220,000 records. ITmedia also reported that Citizen Watch said data on about 100,000 people may have been affected. [ 2 , 8 ]
Sompo Japan said that, as far as it had confirmed at the time of the announcement, there was no unauthorized use of the data and no publication or spread online. It said it would investigate the cause together with Scala Communications, press for thorough measures to prevent recurrence, and review how it manages subcontractors, deciding on tougher controls and when to implement them. [ 2 ]
The announcement came as Japanese companies reported a series of possible data leaks through outside vendors, with Daiwa Securities and Citizen Watch among those naming the same provider. [ 2 , 6 , 8 ]
Why it matters
The case points to risk concentrated in shared outside vendors: one breach at a FAQ-system provider may have exposed data held by several companies at once. Sompo Japan says it will review how it manages subcontractors, and the disclosures by Daiwa Securities and Citizen Watch suggest the fallout may extend beyond a single insurer.
Key facts
- Sompo Japan announced on October 7 that about 60,000 customer records may have leaked after unauthorized access to a subcontractor's server. [ 1 , 2 , 3 , 4 , 5 , 6 , 7 , 8 ]
- The server was used to handle inquiries for “SMILING ROAD”, a communication-enabled dashcam service for businesses. [ 2 , 6 , 7 , 8 ]
- Potentially exposed data includes names, phone numbers, addresses, email addresses, employer and department names, driver IDs, alert types and dates, dashcam serial numbers, application numbers and inquiry subjects and text. [ 2 , 8 ]
- Sompo Japan says bank account, credit card and My Number card information is not included. [ 2 , 8 ]
- The roughly 60,000 figure counts repeat inquiries by the same person more than once. [ 2 ]
- The vendor is Scala Communications of Shibuya, Tokyo, which provides the FAQ system “i-ask”. [ 2 , 8 ]
- Scala Communications says a third party logged into the i-ask administration site from around 20:33 on October 2 to around 08:01 on October 3 and installed a malicious program. [ 2 ]
- Daiwa Securities, which also uses the vendor, disclosed a possible leak on October 5, and Citizen Watch has also announced one. [ 2 , 8 ]
Confirmed by several sources
- Sompo Japan announced on October 7 that about 60,000 customer records may have leaked after unauthorized access to a subcontractor's server. [ 1 , 2 , 5 , 6 , 7 , 8 ]
- The affected server was used for handling inquiries about the business-oriented dashcam service “SMILING ROAD”. [ 2 , 6 , 7 , 8 ]
- Potentially exposed data includes names, addresses, phone numbers and employer information, while credit card and My Number card data is not included. [ 2 , 8 ]
- The vendor concerned is Scala Communications, which provides inquiry-handling systems for companies. [ 2 , 8 ]
- Daiwa Securities, which also uses the vendor, has announced a possible leak of customer information. [ 2 , 8 ]
Still unclear
- The number of Daiwa Securities records affected. ITmedia reported about 220,000 records, while Nippon TV News said 110,000 customers; the two figures do not match and the documents do not reconcile them.
- The full scale of the vendor-side breach. Scala Communications' figures of up to five companies and up to 713,126 records come from a single document, and the other companies are not named.
- Whether the leaked data has been misused or published. Sompo Japan says that, as far as it has confirmed at the time of the announcement, there is no unauthorized use, online publication or spread; this is a point-in-time statement.
- Citizen Watch's possible leak. Mentioned only in one document, which says about 100,000 people's data may be affected.
What local media are saying
Timeline, local time
- A third party begins unauthorized logins to the i-ask administration site, according to Scala Communications. [ 2 ]
- The unauthorized access to the i-ask administration site ends, according to Scala Communications. [ 2 ]
- Daiwa Securities discloses that 110,000 customers' information may have leaked via the same vendor, according to Nippon TV News. [ 8 ]
- Livedoor News reports the possible leak of about 60,000 Sompo Japan customer records. [ 1 ]
- ITmedia reports the breach, naming Scala Communications and its i-ask system. [ 2 ]
- Nishi-Nippon Shimbun reports the possible leak of about 60,000 customer records. [ 3 ]
- Tokyo Shimbun reports the possible leak. [ 4 ]
- NHK News reports Sompo Japan's announcement of about 60,000 records possibly leaked. [ 5 ]
- Yahoo! News Japan reports the possible leak and that no misuse has been confirmed. [ 6 ]
- TBS NEWS DIG reports that the breach was at a subcontractor's server handling dashcam inquiries. [ 7 ]
- Nippon TV News reports the possible leak and links the vendor to Daiwa Securities. [ 8 ]