Nippon Columbia malware incident exposes 8.6 million karaoke fan records

Nippon Columbia malware incident exposes 8.6 million karaoke fan records

Daiichi Kosho, a major Japanese entertainment system maker, disclosed that a malware infection at its contractor, Nippon Columbia, exposed more than 8.7 million customer and employee records.

The company is the largest karaoke maker in Japan, operating 521 karaoke venues nationwide, including the Big Echo chain, one of the most popular karaoke box chains in the country.

Daiichi Kosho outsources the handling of its customers’ personal information to Nippon Columbia Group (NCG), a Japanese entertainment group whose businesses include music, video and game software production and distribution, as well as artist management.

The record company informed Daiichi Kosho on October 5 that it had discovered malware on an employee’s computer and isolated the affected system the following day.

Daiichi Kosho says it has not confirmed any data theft or leaks but is advising customers to remain cautious due to the potential risk.

The company says the exposed data contains records for 93,000 employees and 8,631,000 customers, which include:

  • Full names
  • Genders
  • Dates of birth
  • Email addresses
  • Telephone numbers

The entertainment giant says that the incident may impact customers of BIG ECHO, MEGA BIG, Karaoke CLUB DAM, Banana Club, B-GARAGE, and DK Dining.

The general recommendation is to be suspicious of unsolicited communication via email, SMS, or phone calls requesting payments or sensitive personal or financial information.

The firm says that the exposed data does not include passwords, and there is no evidence of unauthorized use of loyalty points.

Daiichi Kosho said its own systems were not breached, noting that NCG reset passwords and other authentication credentials and is investigating the cause and scope of the incident, as well as whether any data has been leaked online.

An update on Friday does not provide additional information about the possibility of a data leak

BleepingComputer could not find a public announcement from NCG about this security incident. We have contacted the firm for more details and are awaiting a statement.

article image

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat