Japanese entertainment systems maker Daiichi Kosho has disclosed that a malware infection at one of its contractors, Nippon Columbia, exposed records relating to approximately 8.6 million customers and employees, according to a report by BleepingComputer. The compromise occurred on Nippon Columbia's systems; Daiichi Kosho, the operator of several karaoke brands, is the owner of the affected data and the party making the disclosure.

The public record remains limited. Daiichi Kosho said the records of over 8.6 million people were exposed through the malware event. The initial access vector, dwell time, malware strain, and containment timeline have not been disclosed, and there is no attribution to any named threat actor. There is no public indication, at this stage, that the records have been listed or sold on underground forums.

Context for security teams

The incident illustrates a pattern common in third-party breaches: the party penetrated is not the party that answers for the consequences. Daiichi Kosho does not appear to have been directly compromised, yet it owns the customer-notification and reputational fallout because the records were its customers' and employees'. Questions this raises for supplier assurance include whether organisations can enumerate every third party holding their personal data; whether contracts require breach notification within a defined window; whether security and notification obligations flow down to subcontractors; and whether incident response playbooks account for compromises at suppliers the organisation does not directly operate.

For organisations in Hong Kong, one relevant regulatory principle under the Personal Data (Privacy) Ordinance is that the data user remains responsible for taking practicable steps to secure personal data processed on its behalf by third parties — outsourcing processing does not outsource accountability. No Hong Kong entities are reported to be involved in this incident; the PDPO reference is included as general context only.1

Daiichi Kosho has yet to publish detail on how the contractor was compromised or when the infection was detected. If either company releases further technical information, or if the data surfaces on an underground marketplace, this story will warrant revisiting.


  1. The PDPO principle cited is a general obligation applying to all data users in Hong Kong; the Nippon Columbia / Daiichi Kosho incident is reported to involve Japanese entities only. ↩


據 BleepingComputer 報道,日本娛樂系統製造商第一興越(Daiichi Kosho)披露,其承辦商之一日本哥倫比亞(Nippon Columbia)遭惡意軟件入侵,涉及約860萬名客戶及員工的紀錄外洩。入侵事件發生在日本哥倫比亞的系統上;第一興越作為多個卡拉OK品牌的營運商,則是受影響資料的持有人,亦是作出披露的一方。

公開資料仍然有限。第一興越表示,超過860萬人的紀錄因該次惡意軟件事件而外洩。至於初始入侵途徑(initial access vector)、潛伏時間(dwell time)、惡意軟件種類以及遏制時間表,均未有披露,亦未有指明任何具名的威脅行為者(threat actor)。現階段亦沒有公開跡象顯示相關紀錄已在地下論壇上架或出售。

保安團隊須注意的背景

今次事件反映第三方外洩事故中的常見模式:被入侵的一方,往往不是為後果負責的一方。第一興越看來並未直接受到入侵,但由於受影響資料屬於其客戶及員工,客戶通知及聲譽後果卻須由它承擔。此事為供應商保障(supplier assurance)帶來的相關問題包括:機構能否逐一列出所有持有其個人資料的第三方;合約是否要求在指定期限內通報資料外洩;保安及通報責任是否貫徹至分判商;以及事故應變指引(incident response playbook)是否涵蓋機構並未直接營運的供應商遭入侵的情況。

對香港的機構而言,《個人資料(私隱)條例》(PDPO)一項相關原則是:資料使用者須為代其處理個人資料的第三方,採取切實可行的保障措施——將處理工序外判,並不等於將責任外判。據悉,今次事件並無香港機構牽涉其中;此處引用 PDPO 僅作為一般背景參考。1

第一興越尚未公布承辦商如何被入侵,以及何時偵測到感染。倘若兩家公司其後公布更多技術資料,或若相關資料出現在地下市場,此事件就值得重新審視。


  1. 此處引用的 PDPO 原則,屬適用於所有香港資料使用者的一般責任;據報日本哥倫比亞/第一興越事件只牽涉日本機構。 ↩

新聞來源 / Original News Source