Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Asahi Data Breach Impacts 2 Million Individuals

Hackers stole the personal information of customers and employees before deploying ransomware and crippling Asahi’s operations in Japan.

Asahi ransomware data breach

Japanese beer giant Asahi on Thursday announced that hackers stole the personal information of roughly 2 million individuals in a disruptive ransomware attack in September.

Asahi disclosed the incident on September 29, the same day that it occurred. Its operations in Japan continue to be partially disrupted, as the impacted systems are gradually being restored.

In early October, the Qilin ransomware group added Asahi to its Tor-based leak site, claiming the theft of 27 gigabytes of data.

Days before that, Asahi announced that hackers had exfiltrated data from its systems. Now, it has confirmed that personal information was compromised in the attack.

According to the company, 1,525,000 people who contacted its customer services had their names, addresses, phone numbers, and email addresses stolen.

The hackers also exfiltrated the names, addresses, and phone numbers of 114,000 people Asahi had sent congratulatory or condolence messages to.

Advertisement. Scroll to continue reading.

Additionally, 107,000 Asahi employees had their names, addresses, phone numbers, email addresses, dates of birth, and gender information stolen. The hackers also stole the names, dates of birth, and gender data of 168,000 family members of current and former employees.

“We have not confirmed any instance of this data being published on the internet,” Asahi said on Tuesday.

Asahi noted that the compromised information varies by individual and that no credit card information was stolen.

The company explained that the threat actors hacked network equipment, and used it to compromise its data center network.

“Ransomware was deployed simultaneously, encrypting data on multiple active servers and some PC devices connected to the network,” the company said.

It also explained that it has been scrambling to contain the ransomware, and that it would restore only systems and devices confirmed to be secured, in phases.

“We are making every effort to achieve full system restoration as quickly as possible, while implementing measures to prevent recurrence and strengthening information security across the Group,” Asahi Group president and CEO Atsushi Katsuki said.

“Regarding product supply, shipments are resuming in stages as system recovery progresses. We apologize for the continued inconvenience and appreciate your understanding,” Katsuki added.

In an emailed comment, Immersive senior manager Kevin Marriott pointed out that Qilin is known to leak data stolen from companies that do not pay a ransom and that Asahi’s customers should continue to monitor for updates.

“Manufacturing networks are complex ecosystems, potentially containing legacy systems, shadow IT, diverse technologies, and connectivity with supply chains and other third-party entities,” Marriott said.

“As a result, when impacted, full recovery is a timely process, especially when assuring all artifacts of compromise have been identified and removed, which is likely why it is likely to be February before a return to normalized operations is achieved,” he added.

Related: Ransomware Attack Disrupts Local Emergency Alert System Across US

Related: Pennsylvania Attorney General Confirms Data Breach After Ransomware Attack

Related: Akira Ransomware Group Made $244 Million in Ransom Proceeds

Related: Synnovis Confirms Patient Information Stolen in Disruptive Ransomware Attack

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

People on the Move

Anurag Jain has been appointed Senior Vice President of Engineering at CodeHunter

CTERA has appointed Tal Sarfaty as Senior Vice President of Cybersecurity.

Quantum Secure Encryption has named Michael Massing as Chief Technology Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.