Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Thousands Impacted by Casio Data Breach

Casio has completed its investigation into the data breach caused by a recent ransomware attack and found that thousands of individuals are impacted.

Casio ransomware

Japanese electronics giant Casio has completed its investigation into the data breach caused by a recent ransomware attack and found that thousands of individuals are impacted.

The company revealed in early October 2024 that some systems had failed and some services had been disrupted as a result of unauthorized access to its network. 

A few days later it confirmed that it had been targeted in a ransomware attack that resulted in personal information and confidential corporate files getting stolen. 

Casio has now completed its forensic investigation and determined exactly what type of data has been compromised, as well as how the attackers gained access to its systems.

The company’s report indicates that the attackers gained access through vulnerabilities in overseas offices. It suggests that initial access was achieved with the aid of phishing emails. 

Casio has confirmed that corporate documents and other internal data was compromised, mainly taken from servers hit by the ransomware. 

Advertisement. Scroll to continue reading.

Employees’ personal information and information on some business partners and customers was also taken by the cybercriminals. Nearly 6,500 employees from Japan and other countries are impacted. The exposed information includes name, email address, gender, date of birth, and taxpayer ID — different types of information was compromised for different employees.

Casio said roughly 1,900 business partners are impacted, including information such as name, representative, email address, phone number, company name and contact details, and — in a couple of cases — ID cards. 

In terms of customers’ personal information, the name, phone number, address, date of purchase, and product name of 91 customers who acquired products in Japan and needed delivery and installation was impacted. 

However, Casio noted, “No evidence of data theft was found in the customer database or in the system that handles customers’ personal information.”

In addition, Casio found that invoices, contracts, sales documents, meeting and internal review materials, and data related to internal systems was also stolen by the cybercriminals. Payment card information was not included in the compromised files.

A ransomware group named Underground took credit for the attack and threatened to leak stolen files shortly after the data breach came to light. 

The cybercriminals claim to have stolen over 200 Gb of data from Casio and they appear to have made at least some of it available for download by anyone who can access their Tor leak website. 

Related: IT Giant Atos Responds to Ransomware Group’s Data Theft Claims

Related: Washington Attorney General Sues T-Mobile Over 2021 Data Breach

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

SolarWinds has appointed Justin Henkel as Chief Information Security Officer.

J. Paul Haynes has joined Cinchy as Chief Executive Officer.

Hatem Naguib has become Chief Executive Officer at Sysdig.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.