Data leaks have accelerated lately and become almost a daily occurrence.

According to a Jiji Press report[1], on the 10th the Tokyo Chamber of Commerce and Industry announced that it had suffered a targeted attack and data leak. Lists of seminar participants from the past 3 years, stored on the International Affairs Division’s file-sharing server, were reportedly leaked. The data included names, telephone numbers, email addresses, and company names, but no financial information such as bank or securities account details. The Metropolitan Police Department reportedly plans to investigate, including possible use of malicious electronic records. The incident was reported to the Ministry of Economy, Trade and Industry on the 4th[2].

The article further states:

Because access to the personal information was limited to International Affairs Division employees, no password had been set. No damage has been reported at present, and only 1 computer was infected.

…orz. I wish people would abandon this perimeter-security mindset. Apply proper access control to the data itself.

Wait. “No password had been set” is oddly phrased. Perhaps the data were not in a database accessible only from the division’s IP addresses, but in an Excel or similar file that simply lacked password protection…

Footnotes:

[1] Jiji Press, “Up to 10,0002000 Member Records Leaked after PC Virus Infection; Metropolitan Police Investigate TCCI” http://www.jiji.com/jc/zc?k=201506/2015061000093&g=soc (accessed 2015/6/10)

[2] Jiji Press, “Chief Cabinet Secretary Suga Calls for Prevention of Recurrence after TCCI Information Leak” http://www.jiji.com/jc/zc?k=201506/2015061000403&g=eco

 

Related posts

Thoughts on the Benesse Personal Data Breach

It appears that children's and other personal data—up to 20.7 million records—was leaked[1] from Benesse. This is a thought-provoking incident in many respects. Let us consider…

Identity · 2014-07-11