Casio confirms data of 8,500 people exposed in recent ransomware attack

Code Skull
(Image credit: Shutterstock)

  • Casio confirms 8.5k people lost their data in October 2024 ransomware attack
  • Most are Casio employees, with partners and customers less affected
  • The company says it did not pay the ransom demand

Personal data on 8,500 people, mostly Casio employees, was stolen during the October 2024 ransomware attack against the Japanese electronics manufacturer, the company confirmed in an announcement posted on its website.

The incident saw a threat actor from the Underground ransomware group gain access to the company’s IT infrastructure through a successful phishing attack. From there, they were able to disrupt the company’s network, steal sensitive information, and demand a ransom payment.

At the time, the company could not say exactly who was affected by the breach, or what kind of information was stolen - now, a subsequent investigation has shown the data mostly belongs to company employees, with a smaller amount belonging to business partners, and customers.

Employees, business partners, and customers

Overall, 6,456 employees lost their names, employee numbers, email addresses, affiliations, genders, dates of birth, family details, addresses, phone numbers, taxpayer ID numbers, and HQ system account information.

1,931 business partners also lost their names, email addresses, and phone numbers, but also company names, company addresses, and ID card information.

Finally, 91 customers lost their delivery addresses, names, phone numbers, dates of purchase, and product names.

Other leaked data includes internal documents such as invoices, contracts, and meeting materials. Credit card and other payment information was not taken.

Casio stressed that it did not negotiate with the attackers, and did not pay any ransom demand. All affected individuals have been alerted. Usually, when a threat actor steals sensitive information but does not receive a payment, they end up selling the data on the dark web, or using it in phishing, identity theft, or similar attacks.

So far, that doesn’t seem to have been the case, since Casio says there is no evidence of in-the-wild abuse yet.

Via BleepingComputer

You might also like

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Casio logo
Casio’s online store hit by bogus credit card stealing checkout form
Insurance
Globe Life data breach may have affected 850,000 more patients than previously thought
ransomware avast
Engineering giant ENGlobal confirms hackers hit internal data
Ransomware
Atos now says its systems weren't hit by a ransomware attack after all
An abstract image of padlocks overlaying a digital background.
US healthcare giant Ascension says ransomware attack affected nearly six million customers
ransomware avast
The biggest addiction treatment provider in the US says it was hit by data breach
Latest in Security
China
Chinese hackers who targeted key US infrastructure charged by Justice Department
linkedin
Watch out - that LinkedIn email could be a fake, laden with malware
An American flag flying outside the US Capitol building against a blue sky
Mass federal layoffs will have “devastating impact on cybersecurity, former NSA cybersecurity director warns
A hand reaching out to touch a futuristic rendering of an AI processor.
North Korean fake job hackers are going the extra mile to make sure their scams seem legit
A hand reaching out to touch a futuristic rendering of an AI processor.
Google Cloud unveils new AI Protection security tools, no matter which model you use
A TV remote pointing at YouTube logo
YouTube warns of phishing video using its CEO as bait
Latest in News
Stock photographs of people smiling and looking at laptops in a small business environment.
This web hosting platform elevates your online presence
The Samsung Galaxy S25 Edge on display at Galaxy Unpacked
Exclusive: the Samsung Galaxy S25 Edge will have durability to match its ‘sexy’ form
Metaphor: ReFantazio
Sega was Metacritic's highest-rated publisher of 2024 thanks to the critically acclaimed Metaphor: ReFantazio and Like a Dragon: Infinite Wealth
AirPods Pro Review
Apple has quietly updated its guidance on how to clean your AirPods, and suggests you buy a kit… from Belkin
China
Chinese hackers who targeted key US infrastructure charged by Justice Department
A screen shot of Lady Gaga in her interview with Zane Lowe for Apple Music
Lady Gaga’s Spotify press conference is being live streamed today – here’s where you can watch Spotify’s big step forward in fan inclusion