Global electronics firm Casio has admitted that deficiencies in its security systems resulted in a ransomware attack last October, which saw the company’s servers illegally accessed from overseas.
Publishing the results of an investigation into the incident, Casio said that despite measures in place against phishing emails, its security systems were unable to counter the ‘cunning ransomware attacks’ which resulted in the leak of internal company documents and the personal data of almost 8,500 people, mostly Casio employees and business partners, being accessed.
The details of ninety-one Casio customers were apparently also leaked, including the delivery addresses, names, and telephone numbers of customers who purchased some products in Japan, but the company said that no credit card data was lost.
The Tokyo-headquartered firm said that no evidence of data theft was found in its customer database or in the system that handles customers’ personal information.
Other information leaked included data related to contracts and sales, internal meeting materials, and systems data, however the company said that there was no leakage of insider-related information.
Although the ransomware attack had previously been claimed by the Underground group, Casio declined to confirm the identity of the attacker, stating simply that the company had not responded to any “unreasonable demands” from those that carried out the attack, suggesting that no payment was made.
However, the firm said that some of its employees had received unsolicited spam emails that could be related to the attack, but that there have been no reports of secondary damage to business partners or customers.
“Casio would like to reiterate its deepest apologies to all parties involved for any inconvenience caused,” said the firm’s statement.
Recommended reading
- Ransomware Groups are Adjusting Their Strategies
- NCSC Guide: How To Bridge Cyber With The Boardroom
- NCSC Warns Ransomware Threat to Rise with AI
Instances of ransomware attacks grew last year, with a report from Searchlight Cyber in September finding that the number of active ransomware groups had increased by 56% around the world.
Another report revealed that 69% of businesses affected by ransomware attributed the increase in attacks to phishing incidents made more effective through AI technology, with more than half believing that the increased use of AI by cyber-criminals had made their companies more vulnerable.





