Customer data for ~110,000 people may have leaked via unauthorized access at an outsourced vendor, exposing Daiwa Securities to a data-security/legal-compliance issue.
Daiwa Securities, a subsidiary of Daiwa Securities Group, announced on the 5th that customer information for approximately 110,000 people may have been leaked due to unauthorized access to a server at an outsourced vendor. The potentially leaked information includes names, email addresses, and account numbers, and when inquiries and other information that cannot identify individuals is included, the total reaches approximately 220,000 records. The unauthorized access occurred between around 8:33 p.m. on the 2nd and around 8:01 a.m. on the 3rd at Scalar Communications, a system company to which Daiwa Securities outsources the provision of inquiry management services, and Daiwa Securities received a report from the company on the 3rd. Scalar Communications has already implemented emergency security enhancements, and at this point no additional unauthorized access or information leaks have been confirmed, nor has any unauthorized access to Daiwa Securities' own systems been confirmed. The potentially leaked information alone cannot be used to access securities accounts or conduct transactions, and at this point no fraudulent transactions resulting from this matter, nor any public disclosure or spread of the information on the internet, have been confirmed.
Customer data for ~110,000 people may have leaked via unauthorized access at an outsourced vendor, exposing Daiwa Securities to a data-security/legal-compliance issue.