Karaoke operator Daiichikosho says 8.72 million personal records may have leaked
In short
Daiichikosho (第一興商), which runs Big Echo (ビッグエコー) karaoke shops, said on October 8 that about 8.72 million records of personal information may have leaked after malware infected a device of an employee at a contractor that handles its personal data. The records cover customers and employees and include names, gender, dates of birth, phone numbers and email addresses, Asahi Shimbun reported. The company said it had not confirmed so far that any information actually leaked or was misused.
Read the full story 2 min read
Daiichikosho (第一興商), which operates karaoke shops including Big Echo (ビッグエコー), said on October 8 that personal information covering about 8.72 million records may have leaked after a device belonging to an employee of a company it contracts to handle personal information was infected with malware. [ 1 , 2 , 4 ]
Asahi Shimbun reported that the data cover members of the company's services, such as Big Echo karaoke shops and DK Dining (DKダイニング) restaurants, as well as Daiichikosho employees, totalling about 8,724,000 records, and include names, gender, dates of birth, phone numbers and email addresses. TBS NEWS DIG gave the same total and listed names, gender, dates of birth and phone numbers of customers and employees. Nikkei reported about 8.63 million records, including customer information registered for Big Echo membership, and about 90,000 employee records, and said registered names, phone numbers and email addresses may have been exposed. [ 1 , 4 , 5 ]
According to Daiichikosho's announcement as reported by Asahi Shimbun, one PC of an employee of the Nippon Columbia group (日本コロムビア) in Tokyo, which handles personal information on its behalf, was found by October 2 to be infected with malware, and Daiichikosho received a report on October 5. Nikkei reported that the Nippon Columbia group, based in Shibuya, Tokyo, received unauthorised access on October 1–2. TBS NEWS DIG reported that the company attributed the incident to a cyberattack on a device of an employee at the contractor. [ 1 , 4 , 5 ]
Daiichikosho said it has not so far confirmed that the information actually leaked outside or has been misused, Nikkei reported, and that it will keep monitoring the situation and take necessary measures if it finds signs of misuse. [ 1 ]
The company warned that the information could be misused for spoofed emails and phishing fraud, TBS NEWS DIG reported, and urged people to watch for suspicious emails and phone calls. Asahi Shimbun said the company also warned about suspicious text messages and that inquiries can be made at 03-3280-3702 on weekdays from 10 a.m. to 5 p.m. [ 4 , 5 ]
Why it matters
Daiichikosho warned that the information could be misused for spoofed emails and phishing fraud, and urged people to watch for suspicious emails and phone calls. The incident was traced to a contractor that handles personal information for the company, according to its announcement.
Key facts
- Daiichikosho said about 8.72 million records of personal information may have leaked. [ 1 , 2 , 3 , 4 , 5 ]
- The company made the announcement on October 8. [ 1 , 4 ]
- A device of an employee at a contractor that handles Daiichikosho's personal information was infected with malware. [ 2 , 4 ]
- The contractor is the Nippon Columbia group (日本コロムビア) in Tokyo. [ 1 , 4 ]
- The records include information on Big Echo karaoke customers and on employees. [ 1 , 4 , 5 ]
- The data include names, gender, dates of birth, phone numbers and email addresses, Asahi Shimbun reported. [ 4 ]
- Nikkei reported about 8.63 million customer records, including Big Echo member registrations, and about 90,000 employee records. [ 1 ]
- Daiichikosho said it had not confirmed any actual leak of the information or misuse so far. [ 1 ]
Confirmed by several sources
- About 8.72 million records of personal information may have leaked. [ 1 , 2 , 3 , 4 , 5 ]
- The incident stemmed from a device of an employee at a contractor that handles Daiichikosho's personal information. [ 2 , 4 , 5 ]
- The contractor is the Nippon Columbia group in Tokyo. [ 1 , 4 ]
- Information on Big Echo customers and on employees is included. [ 1 , 4 , 5 ]
- Names, dates of birth and phone numbers are among the data that may have leaked. [ 4 , 5 ]
- Daiichikosho urged people to watch for suspicious emails and phone calls. [ 4 , 5 ]
Still unclear
- Whether any information actually left the contractor's systems. Outlets report only that a leak may have occurred, and Nikkei reported that Daiichikosho has not confirmed an actual leak or misuse so far.
- Exactly which data items are affected. Nikkei lists registered names, phone numbers and email addresses; TBS NEWS DIG lists names, gender, dates of birth and phone numbers; Asahi Shimbun lists all of these including email addresses.
- How the malware reached the contractor's device. Nikkei reported unauthorised access on October 1–2 and Asahi Shimbun said the infection was found by October 2, but no document says how it happened.
What local media are saying
Timeline, local time
- Nikkei reports Daiichikosho's announcement that about 8.72 million personal records may have leaked. [ 1 ]
- NHK reports the malware infection at the contractor and the possible leak. [ 2 ]
- Livedoor News reports that names and dates of birth are among the data that may have leaked. [ 3 ]
- Asahi Shimbun reports the data types and that Daiichikosho was told of the infection on October 5. [ 4 ]
- TBS NEWS DIG reports the company's warning about spoofed emails and phishing fraud. [ 5 ]