Daiichi Kosho data exposed in Nippon Columbia malware incident
According to BleepingComputer, Japanese karaoke maker Daiichi Kosho has disclosed that a malware infection at its contractor, Nippon Columbia, exposed more than 8.7 million customer and employee records. The company says it has not confirmed any data theft or leak, but it is warning affected people to stay alert. The Nippon Columbia malware incident is a reminder of how much personal data sits with outsourced processors.
What we know
- Daiichi Kosho outsources the handling of customer personal information to Nippon Columbia Group (NCG), an entertainment group active in music, video and game publishing and artist management.
- On October 5, NCG told Daiichi Kosho it had found malware on an employee’s computer.
- The affected system was isolated the following day.
- NCG reset passwords and other authentication credentials and is investigating the cause and scope, including whether any data has been leaked online.
- Daiichi Kosho states that its own systems were not breached.
A Friday update from the company reportedly added nothing further on whether data was leaked.
Who is affected
Daiichi Kosho reports the exposed records cover about 93,000 employees and 8,631,000 customers. The data fields listed are:
- Full names
- Genders
- Dates of birth
- Email addresses
- Telephone numbers
The company says passwords were not part of the exposed data and that it has seen no evidence of unauthorised use of loyalty points. Customers of BIG ECHO, MEGA BIG, Karaoke CLUB DAM, Banana Club, B-GARAGE and DK Dining may be affected. Daiichi Kosho operates 521 karaoke venues in Japan, including the Big Echo chain.
What has not been confirmed
- Whether any data was actually stolen or published. Daiichi Kosho has not confirmed theft or a leak.
- The malware type, the initial infection route and the attacker: not disclosed.
- NCG’s own position. BleepingComputer says it could not find a public NCG announcement and has asked for comment.
Note a small difference in the figures: the headline cites 8.6 million records, while the company’s breakdown (93,000 employees plus 8,631,000 customers) adds up to roughly 8.7 million in total.
Why this matters
Analysis, not new facts. The fields involved (name, date of birth, email, phone) are exactly what phishing and smishing campaigns need to sound credible. Even if no leak is ever confirmed, anyone in the affected population should expect convincing messages posing as the brand, a payment service or a delivery company. The incident also shows third-party risk: the data controller’s own systems were reportedly untouched, yet the exposure came through a processor’s single endpoint.
What to do
For affected customers:
- Treat unsolicited email, SMS or calls asking for payment or personal or financial details as suspicious, as Daiichi Kosho advises.
- Do not click links in messages claiming to be about this incident. Use the company’s official site instead.
- Change the password on any account where you reused credentials, even though passwords are said not to be exposed.
For security teams:
- Inventory which vendors process your customer or employee personal data and what incident-notification terms they are bound by.
- Ask processors how quickly they isolate endpoints and rotate credentials, as NCG did here.
- Brief help desks and customer support on likely phishing themed around the incident, and consider monitoring for look-alike domains.
- Hunt for endpoint malware alerts on staff who handle bulk personal data, and confirm EDR coverage on those machines.
