Daily NewsCyber Crime & Forensic

Japanese Retailer Askul Confirms Data Leak After Ransomware Attack Early in October

Contact Information, Inquiry Details, and Supplier Data Among Those Compromised in Breach

Askul, a well-known Japanese office and household goods retailer, has confirmed the fallout from a cyberattack last month: customer and supplier data getting leaked.

The data leak comes after a ransomware attack on Askul in October purportedly perpetrated by the cybercrime group RansomHouse. The initial attack disrupted Askul’s operations across its e-commerce platforms and adversely impacted the business of major Japanese retailers, like Ryohin, The Loft, and Muji, both of which rely on Askul’s wide logistics network.

Askul Admits Data Leak, Apologises for Inconvenience

Now, the fallout continues, with the retail giant announcing that the RansomHouse attack exposed contact information and inquiry details of Askul, Lohaco, and Soloel Arena users, as well as supplier data stored on the company’s internal servers. Askul has not specified the exact scope of the leak—the exact number of leaked contact information, for instance—but if RansomHouse is to be believed, the extent could be considerable. The group, in claiming responsibility for the attack, has said it stole 1.1TB of data.

“We sincerely apologise for the inconvenience and concern caused to our customers, business partners, and other related parties,” the company said in a statement over the weekend.

While the Japanese retail giant has admitted to the data leak, none of the companies relying on the retail giant have come forward announcing any sign of compromise or adverse effects from the attack. Incidentally, this incident is the latest high-profile attack on Japanese companies in recent months, with Asahi Group Holdings as another victim.

Asahi’s attacker is reportedly the Russian-speaking Qilin gang. It is yet to be determined if it is aligned with Russia-aligned threat actors like RansomHouse. The latter has been around since March 2022 and dubs itself a “force for good” as it supposedly attacks companies to expose their vulnerabilities. It is known to extort with the threat of releasing exfiltrated data rather than encrypting it.

Martin Dale Bolima

Martin has been a Technology Journalist at Asia Online Publishing Group (AOPG) since July 2021, tasked primarily to handle the company’s Disruptive Tech Asia and Disruptive Tech News online portals. He also contributes to Cybersecurity ASEAN and Data&Storage ASEAN, with his main areas of interest being artificial intelligence and machine learning, cloud computing and cybersecurity. A seasoned writer and editor, Martin holds a degree in Journalism from the University of Santo Tomas in the Philippines. He began his professional career back in 2006 as a writer-editor for the University Press of First Asia, one of the premier academic publishers in the Philippines. He next dabbled in digital marketing as an SEO writer while also freelancing as a sports and features writer.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *