Casio Hit by Underground Ransomware Causing Major Data Breach

Incident Date: Oct 10, 2024

Attack Overview
VICTIM
Casio Computer Co., Ltd
INDUSTRY
Manufacturing
LOCATION
Japan
ATTACKER
Underground Team
FIRST REPORTED
October 10, 2024

Casio Computer Co., Ltd. Falls Victim to Underground Ransomware Attack

Casio Computer Co., Ltd., a leading Japanese electronics manufacturer, has been targeted by the Underground ransomware group, resulting in a significant data breach. The attack, which occurred on October 5, led to the exfiltration of approximately 204.9 GB of sensitive data, including confidential documents and personal information.

Casio: A Leader in Electronics

Founded in 1957 and headquartered in Shibuya, Tokyo, Casio is renowned for its innovative electronic products, including timepieces, calculators, and electronic musical instruments. The company reported net sales of ¥268.83 billion as of March 31, 2024, and employs around 9,594 individuals globally. Casio's commitment to innovation and quality has established it as a prominent player in the electronics industry.

Details of the Ransomware Attack

The Underground ransomware group infiltrated Casio's network, causing system failures and service disruptions. The attackers accessed and leaked sensitive data, including employee personal information, confidential NDAs, and financial documents. Casio confirmed the breach and is working with external specialists to assess the damage. The company assured that no credit card information was compromised, as it is stored separately.

About the Underground Ransomware Group

The Underground ransomware group, associated with the RomCom cybercrime organization, has been active since July 2023. Known for targeting Windows systems, the group employs sophisticated tactics, including exploiting vulnerabilities like CVE-2023-36884 and using phishing emails. The group distinguishes itself by not altering file extensions during encryption, focusing on high-value targets.

Potential Vulnerabilities and Penetration Tactics

Casio's global operations and extensive data handling make it a lucrative target for cybercriminals. The Underground group likely exploited vulnerabilities in Casio's network infrastructure, possibly through phishing or remote code execution flaws. The breach highlights the importance of effective cybersecurity measures to protect sensitive data.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.