Friday, October 4, 2024
HomeCyber Security NewsCasio Hacked: Customers' Personal Details Exposed

Casio Hacked: Customers’ Personal Details Exposed

Published on

Casio Computer Co., Ltd. has apologized for a data leak due to unauthorized server access. 

The server contained the personal information of customers who registered for its educational web service, “ClassPad[.]net.” The leak affected customers both in Japan and abroad.

The company expressed deep regret for the trouble and worry this incident caused its customers and stakeholders. 

- Advertisement - EHA

The company admitted that it failed to prevent the breach, which was a serious violation of its security standards.

The breach was caused by an external cyber-attack that targeted a database in the development environment for “ClassPad[.]net.” 

The attackers were able to access and leak the personal information of some of Casio’s customers. However, no other assets besides this database were compromised.

Document
FREE Demo

Deploy Advanced AI-Powered Email Security Solution

Implementing AI-Powered Email security solutions “Trustifi” can secure your business from today’s most dangerous email threats, such as Email Tracking, Blocking, Modifying, Phishing, Account Take Over, Business Email Compromise, Malware & Ransomware

Background of the Incident

The breach was discovered on the night of Wednesday, October 11, when Casio’s development team noticed a database failure in the ClassPad.net environment. 

Upon further investigation, they found that on Thursday, October 12, customers’ personal information outside Japan had been accessed and leaked.

The investigation revealed that some network security settings in the development environment had been turned off due to an operational mistake by the company’s system management department. 

The lack of proper operational management and supervision was the main reason for the breach, which allowed an external entity to exploit these weaknesses.

Casio took immediate action to deal with the breach. All databases in the development environment affected by the attack have been made inaccessible from outside the environment. 

The incident has been reported to Japan’s Personal Information Protection Commission and JUAS, the “PrivacyMark” certification organization. 

Casio has consulted with external security experts to conduct further investigations and implement necessary measures. The company is also considering legal actions, including cooperation with law enforcement agencies. Moreover, 

Casio is working with the police in their ongoing investigation.

The data breach exposed the following personal information:

  1. Customer names
  2. Customer email addresses
  3. Country/region of residence
  4. Purchasing information (order details, payment method, license code, etc.)
  5. Service usage information (log data, nicknames, etc.)
  6. Credit card information was not stored.

The number of individuals affected by the breach was large:

  • Customers in Japan: 91,921 items, including 1,108 educational institution customers and individual customers.
  • Customers outside Japan: 35,049 items from 148 countries and regions.

Casio is contacting all customers whose personal information may have been leaked through email and other means. They have set up a dedicated contact point for inquiries from affected customers.

Service Availability

There was no unauthorized access to the “ClassPad.net” application itself. It is still available for use as normal.

Future measures

In its recent notice, Cisco mentioned that it plans to improve its technical safety management by strengthening its security for network routes and databases.

It will also review its operational procedures and enhance its employee education and training. 

And do their best to restore trust and prevent recurrence of such incidents

Protect yourself from vulnerabilities using Patch Manager Plus to patch over 850 third-party applications quickly. Take advantage of the free trial to ensure 100% security.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Prince Ransomware Hits UK and US via Royal Mail Phishing Scam

A new ransomware campaign targeting individuals and organizations in the UK and the US...

Microsoft, DOJ Dismantle Domains Used by Russian FSB-Linked Hacking Group

Microsoft and the U.S. Department of Justice (DOJ) have successfully dismantled a network of...

Cloud Penetration Testing Checklist – 2024

Cloud Penetration Testing is a method of actively checking and examining the Cloud system...

Linux Malware perfctl Attacking Millions of Linux Servers

Researchers have uncovered a sophisticated Linux malware, dubbed "perfctl," actively targeting millions of Linux...

Free Webinar

Decoding Compliance | What CISOs Need to Know

Non-compliance can result in substantial financial penalties, with average fines reaching up to $4.5 million for GDPR breaches alone.

Join us for an insightful panel discussion with Chandan Pani, CISO - LTIMindtree and Ashish Tandon, Founder & CEO – Indusface, as we explore the multifaceted role of compliance in securing modern enterprises.

Discussion points

The Role of Compliance
The Alphabet Soup of Compliance
Compliance
SaaS and Compliance
Indusface's Approach to Compliance

More like this

Prince Ransomware Hits UK and US via Royal Mail Phishing Scam

A new ransomware campaign targeting individuals and organizations in the UK and the US...

Microsoft, DOJ Dismantle Domains Used by Russian FSB-Linked Hacking Group

Microsoft and the U.S. Department of Justice (DOJ) have successfully dismantled a network of...

Linux Malware perfctl Attacking Millions of Linux Servers

Researchers have uncovered a sophisticated Linux malware, dubbed "perfctl," actively targeting millions of Linux...