Visualização normal

Antes de ontemStream principal
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 4, August 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 4, August2026           Saudi Arabian Digital Entertainment Streaming Service User Data Offered for Sale SAFEPAY Ransomware Attack on a South Korean Industrial Gas Manufacturer and Supplier NoName057(16) and BD Anonymous Claim DDoS Attacks Against Major Japanese Organizations and Companies [1] [2] [3] […]
     

Ransom & Dark Web Issues Week 4, August 2026

Por:ATCP
26 de Agosto de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 4, August2026           Saudi Arabian Digital Entertainment Streaming Service User Data Offered for Sale SAFEPAY Ransomware Attack on a South Korean Industrial Gas Manufacturer and Supplier NoName057(16) and BD Anonymous Claim DDoS Attacks Against Major Japanese Organizations and Companies [1] [2] [3] […]
  • ✇Cybersecurity News
  • Sakura Internet Breach Exposes 1.36 Million Customer Accounts Do Son
    Sakura Internet disclosed a breach of its customer management system affecting 1.36 million accounts, though passwords were hashed and salted and no ransom was demanded. Related Posts: Leaked Corporate AWS Keys Expose Full Admin Rights Kimi Work Silently Uploads Five Recent Agent Sessions With Feedback Reports SafePal Data Breach Exposes Order Information of 39,798 Customers The post Sakura Internet Breach Exposes 1.36 Million Customer Accounts appeared first on Daily CyberSecurity.
     
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 3, August 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 3, August 2026         Customer and Operational Data of a South Korean Delivery Platform Offered for Sale Unauthorized Access Incident at a Japanese Cloud and Data Center Services Company ShinyHunters Threatens Data Disclosure Against a U.S. Live-Streaming Platform
     

Ransom & Dark Web Issues Week 3, August 2026

Por:ATCP
19 de Agosto de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 3, August 2026         Customer and Operational Data of a South Korean Delivery Platform Offered for Sale Unauthorized Access Incident at a Japanese Cloud and Data Center Services Company ShinyHunters Threatens Data Disclosure Against a U.S. Live-Streaming Platform
  • ✇ASEC BLOG
  • July 2026 Dark Web Breach Incident Trend Report ATCP
    Note The July 2026 Dark Web Breach Incident Trend Report was compiled based on data breach cases posted on deep web and dark web forums. Due to the nature of some posts, it is difficult to fully verify their accuracy; some posts related to South Korea included AI-generated false data or cases where it could […]
     
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 4, July 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 4, July 2026           Source Code Collection of a South Korean Autonomous Robot Manufacturer Shared on a Cybercrime Forum Qilin Ransomware Attack on a Spanish Public Wastewater Management Organization RansomHouse Ransomware Attack on a Japanese Frozen Food and Logistics Company
     

Ransom & Dark Web Issues Week 4, July 2026

Por:ATCP
22 de Julho de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 4, July 2026           Source Code Collection of a South Korean Autonomous Robot Manufacturer Shared on a Cybercrime Forum Qilin Ransomware Attack on a Spanish Public Wastewater Management Organization RansomHouse Ransomware Attack on a Japanese Frozen Food and Logistics Company
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 3, July 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 3, July 2026           DragonForce Ransomware Attack on a Saudi Arabian Chemical Manufacturer AiLock Ransomware Attack on Japan’s Largest Taxi and Limousine Operator Cyberattack on Japan’s Largest Frozen Food Company Disrupts the Wider Food Supply Chain
     

Ransom & Dark Web Issues Week 3, July 2026

Por:ATCP
15 de Julho de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 3, July 2026           DragonForce Ransomware Attack on a Saudi Arabian Chemical Manufacturer AiLock Ransomware Attack on Japan’s Largest Taxi and Limousine Operator Cyberattack on Japan’s Largest Frozen Food Company Disrupts the Wider Food Supply Chain
  • ✇Firewall Daily – The Cyber Express
  • Nichirei Cyberattack Hits KFC Japan, Disrupts Frozen Food Supply Samiksha Jain
    The Nichirei cyberattack has disrupted food deliveries across Japan after the frozen food and logistics provider confirmed its servers were compromised in a cybersecurity incident involving unauthorized access. The attack affected logistics operations supporting KFC Japan, forcing temporary service disruptions while the company investigates the incident and works to restore systems. Nichirei Corporation said it detected system failures on July 13 and established an emergency response headquar
     

Nichirei Cyberattack Hits KFC Japan, Disrupts Frozen Food Supply

Nichirei Cyberattack

The Nichirei cyberattack has disrupted food deliveries across Japan after the frozen food and logistics provider confirmed its servers were compromised in a cybersecurity incident involving unauthorized access. The attack affected logistics operations supporting KFC Japan, forcing temporary service disruptions while the company investigates the incident and works to restore systems. Nichirei Corporation said it detected system failures on July 13 and established an emergency response headquarters the same day. "Nichirei Corporation (the "Company") experienced system failures on July 13, 2026, and has since been investigating its cause. The Company hereby announces the facts identified through the investigation to date and the measures it plans to take going forward," reads notice issued by Nichirei. An investigation later confirmed that company servers had been targeted in a cyberattack. While the company has not disclosed technical details to prevent further damage, it said recovery efforts are underway with the support of an external cybersecurity specialist.

Nichirei Cyberattack Disrupts Logistics and Food Shipments

Following the attack, Nichirei disconnected systems across the Nichirei Group to protect customer and business partner data. The decision disrupted inbound and outbound operations at Nichirei Logistics refrigerated warehouses and halted frozen food shipments handled by Nichirei Foods. The company said it plans to gradually resume affected operations from July 17 after implementing additional security measures. Nichirei also confirmed that some affected servers contained personal information. As a precaution, it submitted an initial report to Japan's Personal Information Protection Commission regarding the possibility of a personal information leak. The company emphasized that, as of its latest update, there is no confirmed evidence that personal information or customer data has been exposed externally. Investigations remain ongoing, and Nichirei said it will notify relevant parties if any data leakage is confirmed.

Nichirei Cyberattack Impacts KFC Japan Store Operations

The incident quickly spread beyond Nichirei's own operations, affecting KFC Japan, which relies on Nichirei Logistics to deliver ingredients to stores nationwide. According to KFC Japan, deliveries have been disrupted since July 14 following the unauthorized access at its logistics partner. As inventory levels fluctuate, customers may experience product shortages, limited menu availability, shortened operating hours, or temporary store closures. The restaurant chain also temporarily suspended mobile orders, delivery services, coupons, and online ordering through its official website and mobile application. KFC Japan said it is working closely with Nichirei Logistics and other partners to restore normal operations as quickly as possible. However, it has not provided an estimated timeline for full recovery.

Investigation Continues Into Japan Cyberattack

Nichirei said the financial impact of the incident is still being assessed. The company expects to release its first-quarter financial results for the fiscal year ending December 31, 2026, on August 7 as scheduled unless further developments require additional disclosure. The company added that it will continue investigating the cyberattack on Nichirei and release additional information if material findings emerge. The incident follows a series of recent Japan cyberattack disclosures involving major organizations. Earlier this week, The Cyber Express reported that Nihon Kotsu experienced a malware-related security incident that disrupted taxi dispatch services after portions of its IT infrastructure were taken offline. Earlier this month, The Cyber Express also reported cyber incidents involving Aflac Japan, KDDI, Sapporo Holdings, and Nidec. While those cases affected different industries, attackers frequently gained access through subsidiaries, overseas operations, or third-party infrastructure rather than directly compromising corporate headquarters. Separately, Asahi Group Holdings continues recovering from a ransomware attack that significantly disrupted online ordering and shipment operations, forcing the company to rely on manual processes.

Supply Chain Risks Remain in Focus

The Nichirei cyberattack highlights how attacks on logistics providers can quickly evolve into broader supply chain disruption affecting downstream businesses and consumers. Although Nichirei has begun restoring operations, investigations into the incident remain active. Authorities are also continuing to examine whether any personal information was compromised while the company works to return logistics services and KFC Japan operations to normal. With multiple high-profile cyber incidents affecting Japanese organizations in recent weeks, the latest disruption highlight he growing operational impact of attacks targeting critical logistics and supply chain infrastructure.
  • ✇Security Affairs
  • Malware Hits Japan’s Largest Taxi Company Nihon Kotsu, Services Temporarily Suspended Pierluigi Paganini
    Japan’s largest taxi operator Nihon Kotsu shut down systems after a malware attack, disrupting dispatch and bookings. Nihon Kotsu, Japan’s largest taxi company, disclosed on July 13, 2026 that its internal systems suffered an unauthorized external access involving malware infection in the early morning hours of Saturday, July 11. The company immediately shut down systems as an emergency measure to contain the damage. As a result, its online car hire reservation system, telephone-based taxi
     

Malware Hits Japan’s Largest Taxi Company Nihon Kotsu, Services Temporarily Suspended

14 de Julho de 2026, 06:05

Japan’s largest taxi operator Nihon Kotsu shut down systems after a malware attack, disrupting dispatch and bookings.

Nihon Kotsu, Japan’s largest taxi company, disclosed on July 13, 2026 that its internal systems suffered an unauthorized external access involving malware infection in the early morning hours of Saturday, July 11. The company immediately shut down systems as an emergency measure to contain the damage. As a result, its online car hire reservation system, telephone-based taxi dispatch service, and several internal systems are currently unavailable.

The company’s public notice was direct about the sequence of events.

“We have recently discovered that our internal systems were subjected to unauthorized external access (malware infection). We sincerely apologize for the great inconvenience and concern this has caused to our customers, business partners, and all other parties involved.” reads the company’s notice. “Upon detecting the unauthorized access, we immediately took emergency measures, including shutting down systems, to prevent further damage. As a result, our hire car web order and reservation management system, telephone-based taxi dispatch service, and some internal systems are currently temporarily unavailable.”

The company took systems offline to contain the threat, but it caused operational disruption.

With the telephone dispatch service down, customers who need a Nihon Kotsu taxi are being directed to use the GO taxi app and select Nihon Kotsu as the company when requesting a ride, or to find a nearby taxi stand or flag one down on the street. It’s a significant operational gap for a company that runs one of Tokyo’s most recognizable fleets, but the manual workaround is functional. The hire car reservation system, which handles advance bookings, remains offline.

Nihon Kotsu confirmed it’s working with external security experts to determine the scope of the securty incident, identify the cause, and analyze logs. The internal network has been isolated to prevent further spread. On the question of personal data exposure, the company said: “We are currently conducting a detailed investigation with specialized agencies into whether and to what extent data has been leaked. At this time, no information leak has been confirmed. However, in the unlikely event that we discover any leak or potential leak of personal information of our customers or related parties, we will promptly make an official announcement and contact those affected individually, in accordance with the law.”

That’s a carefully worded statement: confirmed is doing real work there, and the investigation is still open.

Nihon Kotsu said no data leak has been confirmed. If the investigation finds customer data was exposed, it will notify affected individuals and publicly disclose the incident as required by Japan’s Act on the Protection of Personal Information.

The Japanese firm is prioritizing secure system recovery and will provide updates as the investigation progresses. The company also warned customers to ignore suspicious emails or messages impersonating the firm.

“We are prioritizing the security of our system and the recovery process in a safe environment. We will publish updates on the investigation and recovery status on this website as soon as they become available.” concludes the notice. “Please be careful not to open any attachments or click on any links if you receive any suspicious emails or communications impersonating our company.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

  • ✇ASEC BLOG
  • June 2026 Dark Web Breach Incident Trend Report ATCP
    Note The June 2026 Dark Web Breach Incident Trend Report is based on major data breach cases posted on the deep web and dark web forums. Due to the nature of some sources, it was difficult to fully verify the accuracy of certain information, so the report includes content that requires further verification. Major Issue […]
     

June 2026 Dark Web Breach Incident Trend Report

Por:ATCP
8 de Julho de 2026, 12:00
Note The June 2026 Dark Web Breach Incident Trend Report is based on major data breach cases posted on the deep web and dark web forums. Due to the nature of some sources, it was difficult to fully verify the accuracy of certain information, so the report includes content that requires further verification. Major Issue […]
  • ✇ASEC BLOG
  • June 2026 Dark Web Threat Actor Trend Report ATCP
    Note The June 2026 Dark Web Threat Actor Trend Report focuses on trends among threat actors—including hacktivists—operating on the deep web and dark web. It is noted that the accuracy of some information could not be verified. Major Issues In Malaysia, a series of website defacement and compromise incidents targeting local development agencies and public […]
     
  • ✇Firewall Daily – The Cyber Express
  • Japan’s Aflac, KDDI, Sapporo, Nidec: Four Breaches, One Common Entry Point Samiksha Jain
    Four major Japan cyberattacks reported within two weeks point to a common trend, with attackers gaining access through subsidiaries and third-party infrastructure rather than corporate headquarters. While the incidents affected companies from different industries, including insurance, telecommunications, brewing, and manufacturing, the breaches shared one notable characteristic. Rather than directly compromising corporate headquarters, attackers gained access through subsidiaries, overseas oper
     

Japan’s Aflac, KDDI, Sapporo, Nidec: Four Breaches, One Common Entry Point

Japan cyberattacks

Four major Japan cyberattacks reported within two weeks point to a common trend, with attackers gaining access through subsidiaries and third-party infrastructure rather than corporate headquarters. While the incidents affected companies from different industries, including insurance, telecommunications, brewing, and manufacturing, the breaches shared one notable characteristic.

Rather than directly compromising corporate headquarters, attackers gained access through subsidiaries, overseas operations, or third-party infrastructure.

The affected organizations include Aflac Japan, KDDI, Sapporo Holdings, and Nidec, each of which reported separate cyber incidents during the second half of June 2026. Although the attacks involved different circumstances, the disclosures point to an expanding attack surface that extends well beyond an organization's primary network.

Aflac Japan Breach Exposed Customer Data

Aflac Japan disclosed on June 30 that attackers accessed its Japanese operations between June 15 and June 25. According to the company, approximately 4.38 million customers and agents were affected, with a subset of records including bank account information used for insurance premium payments.

The insurer stated that the incident was limited to its Japanese business and did not affect its U.S. operations.

While the company has not attributed the attack to any specific threat group, the reported tactics resemble social engineering techniques previously associated with Scattered Spider.

KDDI Incident Impacts Millions Through Shared Platform

Telecommunications provider KDDI reported unauthorized access involving an email platform used by multiple Japanese internet service providers.

The company said the incident stemmed from a vulnerability in third-party software, potentially exposing up to 14.22 million email account records across six ISPs.

The breach demonstrates how a single vulnerability within shared infrastructure can affect multiple organizations simultaneously.

Sapporo Holdings and Nidec Target Overseas Subsidiaries

Sapporo Holdings disclosed suspected unauthorized access involving two overseas subsidiaries, Singapore-based Pokka and Canadian brewer Sleeman. The company detected suspicious activity, shut down affected systems, and launched an investigation to determine whether any information had been accessed or stolen.

Meanwhile, manufacturing company Nidec confirmed a ransomware attack targeting its Taiwanese subsidiary, Nidec Chaun Choung Technology.

The BlackField ransomware group claimed responsibility for the attack, alleging it had stolen more than two terabytes of company data, including employee, financial, procurement, manufacturing, legal, and IT records. The group reportedly demanded a $2 million ransom.

A Shared Pattern Across the Japan Cyberattacks

Despite involving different industries and attack methods, the four Japan cyberattacks reveal a similar point of compromise.

Aflac's breach was limited to its Japanese business. KDDI's exposure originated from a shared email platform relying on vulnerable third-party software. Sapporo's investigation centers on overseas subsidiaries, while Nidec's ransomware incident affected its Taiwan-based operation rather than its headquarters.

These cases suggest attackers are increasingly targeting subsidiaries, shared services, overseas business units, and technology partners instead of attempting to breach an organization's primary corporate network.

Growing Risks Across the Extended Enterprise

The incidents highlight the importance of treating subsidiaries and external partners as part of the organization's overall security perimeter.

Organizations that rely on overseas offices, acquired businesses, vendors, or shared platforms may inherit additional cybersecurity risks if those environments are not protected to the same standard as corporate headquarters.

The KDDI incident illustrates how third-party dependencies can significantly increase the scale of a breach, while the Nidec cyberattack demonstrates how ransomware groups continue to combine data theft with extortion demands.

The reported tactics observed in the Aflac incident also reinforce the continued effectiveness of social engineering as an initial access method.

While investigations into several of the incidents remain ongoing, the recent disclosures underscore a broader trend. As enterprise environments become increasingly interconnected, subsidiaries, shared infrastructure, and external technology providers are becoming attractive targets for attackers seeking indirect access to larger organizations.

Aflac Data Breach: Over 4M Customers in Japan May Be at Risk

1 de Julho de 2026, 15:25

Aflac says a data breach in Japan may affect 4.38 million customers and agents, exposing personal, policy, and some banking information.

The post Aflac Data Breach: Over 4M Customers in Japan May Be at Risk appeared first on TechRepublic.

  • ✇ASEC BLOG
  • May 2026 Dark Web Breach Incident Trend Report ATCP
    Notes the May 2026 Dark Web Breach Incident Trend Report is organized around the major cases of Data Breaches posted on the deep web and dark web forums. due to the nature of the source, some of the information may not be fully verifiable as to whether it is true or not, and is therefore […]
     
  • ✇ASEC BLOG
  • May 2026 Dark Web Threat Actor Trend Report ATCP
    Notes the May 2026 Dark Web Threat Actor Trend Report summarizes the trends of threat actors and hacktivists operating on the deep web and dark web. some statements are not factually verifiable. Major Issues hacktivist activity targeting the South Korean Region was concentrated. some hacktivist groups claimed DDoS attacks against the website of the South […]
     

May 2026 Dark Web Threat Actor Trend Report

Por:ATCP
8 de Junho de 2026, 12:00
Notes the May 2026 Dark Web Threat Actor Trend Report summarizes the trends of threat actors and hacktivists operating on the deep web and dark web. some statements are not factually verifiable. Major Issues hacktivist activity targeting the South Korean Region was concentrated. some hacktivist groups claimed DDoS attacks against the website of the South […]
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 4, May 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 4, May 2026           Customer Data of Japanese Educational Franchise Sold on BreachForums by Hasan Data from Japanese Government Agency for National Civil Servant Personnel Administration Sold on BreachForums by Hasan FBI Issues Warning Regarding Fraudulent FIFA Websites Ahead of 2026 FIFA […]
     

Ransom & Dark Web Issues Week 4, May 2026

Por:ATCP
27 de Maio de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 4, May 2026           Customer Data of Japanese Educational Franchise Sold on BreachForums by Hasan Data from Japanese Government Agency for National Civil Servant Personnel Administration Sold on BreachForums by Hasan FBI Issues Warning Regarding Fraudulent FIFA Websites Ahead of 2026 FIFA […]
  • ✇Security Boulevard
  • Team Mirai and Democracy Bruce Schneier
    Japan’s election last month and the rise of the country’s newest and most innovative political party, Team Mirai, illustrates the viability of a different way to do politics. In this model, technology is used to make democratic processes stronger, instead of undermining them. It is harnessed to root out corruption, instead of serving as a cash cow for campaign donations. Imagine an election where every voter has the opportunity to opine directly to politicians on precisely the issues they care a
     

Team Mirai and Democracy

24 de Março de 2026, 08:03

Japan’s election last month and the rise of the country’s newest and most innovative political party, Team Mirai, illustrates the viability of a different way to do politics.

In this model, technology is used to make democratic processes stronger, instead of undermining them. It is harnessed to root out corruption, instead of serving as a cash cow for campaign donations.

Imagine an election where every voter has the opportunity to opine directly to politicians on precisely the issues they care about. They’re not expected to spend hours becoming policy experts. Instead, an ...

The post Team Mirai and Democracy appeared first on Security Boulevard.

❌
❌