Daiwa Says Vendor Breach May Have Exposed Records Tied to 110,000 Clients

Daiwa Securities said a breach at service provider Scala Communications may have exposed records linked to 110,000 clients. The brokerage reported no account intrusions or related improper trades as it investigates.
Daiwa Securities office building in Tokyo with a laptop showing a cybersecurity alert Daiwa Securities office building in Tokyo with a laptop showing a cybersecurity alert

Updated:

Daiwa Securities said on Monday, October 5, that information associated with as many as 110,000 clients may have been exposed after unauthorized access to servers operated by its external service provider, Scala Communications. The incident may involve about 220,000 records overall, including entries without information that identifies an individual, according to reporting on the company’s announcement.

Daiwa shares erased earlier gains and fell about 1% in afternoon Tokyo trading, underperforming the broader market, after the disclosure. The company said its own systems were not breached, the information at issue could not be used to access securities accounts or trade online, and it had found no inappropriate transactions linked to the incident.

Possible exposure includes customer identifiers

The potentially affected personal information includes customers’ names, email addresses and securities account numbers. Daiwa has not established publicly the final number of records exposed; the figures describe the possible scope while the company investigates.

Advertisement

The wider count of about 220,000 records includes material that does not identify specific people. That distinction matters: the estimate of 110,000 relates to records tied to individuals, while the larger figure covers additional records involved in the incident.

Unauthorized access occurred at provider’s servers

Daiwa said Scala found evidence of unauthorized access and notified the brokerage. Contemporary reporting in Japan placed the access between the evening of October 2 and the morning of October 3, before Daiwa’s public disclosure on Monday.

The vendor took emergency security measures, while Daiwa said it was examining what information may have been exposed and assessing the incident’s full scope. No public timetable for completing that investigation was given in the available reports.

Daiwa says accounts and trading were not affected

The brokerage’s stated assessment was that the data alone could not be used to log into securities accounts or conduct online transactions. It also said it had not detected improper transactions associated with the incident.

Those statements address account access and observed trading activity, but the investigation into the possible disclosure remains ongoing. Daiwa had not announced a final count of affected customers or records in the reports available on Monday.

Shares retreat after disclosure

Daiwa’s stock, listed in Tokyo under ticker 8601, was down about 1% in afternoon trading after reversing earlier gains. The reported move was an intraday market reaction; it does not establish the incident’s longer-term financial impact.

The breach adds to recent reports of unauthorized access involving Japanese companies. Contemporary coverage also cited incidents affecting Yamato Holdings and Sakura Internet, but the available reports did not establish that those events were connected to Daiwa’s case.

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use
Advertisement