Japan

Country

HOYA Corporation Hit by Cyberattack

February 28, 2019

Japanese optical products manufacturer HOYA Corporation was hit by a cyber attack at the end of February which led to a partial shutdown of its production lines from Thailand for three days.

The company disclosed that around 100 computers were infected with a malware strain designed to steal user credentials from the machines it compromises and to drop a cryptocurrency miner during the infection process’ second stage.

read more

Japanese Auto Parts Manufacturer Yorozu suffers Cyberattack.

October 14, 2024

Japanese auto parts manufacturer Yorozu suffered a cyberattack. The attack forced the company to disconnect and isolate infected systems. The company issued a statement 9 days later saying they are “assessing the extent of the impact and the state of damage. Through our investigations so far, we have confirmed the possibility of some leakage of personal – and confidential information”.

The resulting delay in the submission of the semi-annual report is expected to have financial implications.

read more

Ransomware Attack at Automotive Parts Manufacturer Yorozu

October 14, 2024

Japanese Automotive Parts Manufacturer Yorozu was hit by a Ransomware attack. Files stored on multiple servers were encrypted. A notice published on Yoruzo’s website reads: “Our group immediately set up a task force at our headquarters. … currently investigating the extent of the impact and the extent of the damage.” (machine translated)

read more

DDoS Attack Delays Flights at Japan Airlines

December 26, 2024

Japan Airlines said it was hit by a cyberattack, causing delays to more than 20 domestic flights but the carrier said it was able to stop the onslaught and restore its systems hours later. JAL said the problem started Thursday morning when the company’s network connecting internal and external systems began malfunctioning.

JAL said the issues began around 7:25 a.m., delaying more than 70 domestic and international flights by up to four hours and leading to the cancellation of four domestic flights. While ticket sales were temporarily halted, reservations that had previously been made remained valid. JAL said it determined the cause and that the system was restored at around 1:20 p.m.

Japan Post Co. said mail and parcel deliveries were affected by JAL’s flight disruptions.

read more

Data from Nidec Precision, Vietnam Leaked Online After Negotiations Broke Down

May 26, 2024

One of Nidec Corp’s subsidiaries – Nidec Precision – suffered a cyberattack. Nidec Precision focuses on the design and manufacturing of precision components, particularly in the areas of robotics, electronics, and industrial automation. This company is based in Vietnam.

Among the information stolen in the attack are 50,694 files, including internal documents, letters from business partners, documents related to green procurement, labor safety and health policies, business documents (purchase orders, invoices, receipts), contracts, and more.

The Japanese tech giant says the threat actors tried to extort the company and decided to leak the information after their demands were not met. The attack did not encrypt files and the incident is considered fully remediated at this time.

read more

Cyberattack Impacted Kadokawa’s and its Subsidiary’s Operations.

June 8, 2024

Japanese publisher Kadokawa has confirmed a data leak affecting 254,241 people due to a cyberattack. On June 8, Kadokawa Group subsidiary Niconico suffered a significant ransomware attack that initially compromised its video portal, before affecting the wider Kadokawa Group corporate conglomerate.

This incident has had a ripple effect across the conglomerate, impacting online merchandise orders for stores under the Kadokawa group, as some systems are currently unable to process and ship orders as well as infrastructure related to company-run websites. At one point the perpetrator remotely restarted servers to continue the attack and spread ransomware, forcing staff to physically disconnect power and communications cables from affected servers in order to halt the attack.

The attack halted the flow of orders but also reduced production output and caused delays in physical distribution. The impact is evident in the sudden drop in publication releases as well as the halt in payments to partners. The further shut down of support systems for domestic editing and production of both print and digital publications has compounded the impact of the incident. The ransomware gang BlackSuit claimed responsibility for the attack.

Kyodo News commissioned an investigation and reports on December 12 that $2.98 million in cryptocurrency was paid to BlackSuit on June 13.

read more

Japanese Manufacturer ZARCOS hit by Ransomware Attack

September 14, 2024

Zacros was the victim of a ransomware attack which encrypted some of its servers. An emergency team was set up to investigate the incident and restore the systems, with the help of external experts and the police. The extent of the cyberattack has not yet been fully assessed, but the company apologizes to its partners and customers for the inconvenience caused.

read more

Cyberattack at Japanese Logistics Company Kantsu

September 12, 2024

The Japanese company 関通 (Kantsu) was the victim of a cyberattack with ransomware on September 12, 2024, resulting in the detection of an infection on some of its servers and the cutting of its networks to prevent further attacks. An emergency team was set up to investigate the incident and take measures to repair the damage and prevent new attacks.

read more

Japanese Technology Giant Casio Computer confirmed Cyberattack

October 5, 2024

High tech manufacturer, Casio Computer Co., Ltd., suffered a cyberattack that caused a “system failure” which did not allow the company to provide services.
The Japanese technology giant confirmed on October 5th of this year that its network had been illegally accessed by a third party. The company stated unauthorized access had caused a system failure, making it impossible to provide some services. On October 5, the attackers leaked the data, which included customer names, email addresses, country of residence, order details, service usage information and payment methods. Attackers did not steal credit card information in the breach, the company said. No further information was immediately available.

Just about one year ago the company said hackers accessed the company’s education web application ClassPad.net, resulting in the leak of customers’ personal information from 148 countries.

read more

Allied Telesis Data Breach Claimed by LockBit

May 27, 2024

LockBit has claimed an alleged cyberattack on Allied Telesis, Inc., a prominent American telecommunication equipment supplier. The claimed breach, dated May 27, 2024, suggests that the Allied Telesis data breach exposed sensitive data about the organization. However, the claims have not been verified nor is the sample data posted by the threat actor.

The information supposedly exfiltrated includes confidential project details dating back to 2005, passport information, and various product specifications. As a demonstration of their intrusion, the threat actors purportedly disclosed blueprints, passport details, and confidential agreements, issuing a deadline of June 3, 2024, for the full release of the compromised data.

read more