Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Asahi Data Breach Impacts 2 Million Individuals

Hackers stole the personal information of customers and employees before deploying ransomware and crippling Asahi’s operations in Japan.

Asahi ransomware data breach

Japanese beer giant Asahi on Thursday announced that hackers stole the personal information of roughly 2 million individuals in a disruptive ransomware attack in September.

Asahi disclosed the incident on September 29, the same day that it occurred. Its operations in Japan continue to be partially disrupted, as the impacted systems are gradually being restored.

In early October, the Qilin ransomware group added Asahi to its Tor-based leak site, claiming the theft of 27 gigabytes of data.

Days before that, Asahi announced that hackers had exfiltrated data from its systems. Now, it has confirmed that personal information was compromised in the attack.

According to the company, 1,525,000 people who contacted its customer services had their names, addresses, phone numbers, and email addresses stolen.

The hackers also exfiltrated the names, addresses, and phone numbers of 114,000 people Asahi had sent congratulatory or condolence messages to.

Advertisement. Scroll to continue reading.

Additionally, 107,000 Asahi employees had their names, addresses, phone numbers, email addresses, dates of birth, and gender information stolen. The hackers also stole the names, dates of birth, and gender data of 168,000 family members of current and former employees.

“We have not confirmed any instance of this data being published on the internet,” Asahi said on Tuesday.

Asahi noted that the compromised information varies by individual and that no credit card information was stolen.

The company explained that the threat actors hacked network equipment, and used it to compromise its data center network.

“Ransomware was deployed simultaneously, encrypting data on multiple active servers and some PC devices connected to the network,” the company said.

It also explained that it has been scrambling to contain the ransomware, and that it would restore only systems and devices confirmed to be secured, in phases.

“We are making every effort to achieve full system restoration as quickly as possible, while implementing measures to prevent recurrence and strengthening information security across the Group,” Asahi Group president and CEO Atsushi Katsuki said.

“Regarding product supply, shipments are resuming in stages as system recovery progresses. We apologize for the continued inconvenience and appreciate your understanding,” Katsuki added.

In an emailed comment, Immersive senior manager Kevin Marriott pointed out that Qilin is known to leak data stolen from companies that do not pay a ransom and that Asahi’s customers should continue to monitor for updates.

“Manufacturing networks are complex ecosystems, potentially containing legacy systems, shadow IT, diverse technologies, and connectivity with supply chains and other third-party entities,” Marriott said.

“As a result, when impacted, full recovery is a timely process, especially when assuring all artifacts of compromise have been identified and removed, which is likely why it is likely to be February before a return to normalized operations is achieved,” he added.

Related: Ransomware Attack Disrupts Local Emergency Alert System Across US

Related: Pennsylvania Attorney General Confirms Data Breach After Ransomware Attack

Related: Akira Ransomware Group Made $244 Million in Ransom Proceeds

Related: Synnovis Confirms Patient Information Stolen in Disruptive Ransomware Attack

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar for a practical framework for evolving your AI security program from a single application to an enterprise AI ecosystem and autonomous agents.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Naveen Bhateja has been appointed Chief People Officer at HackerOne.

The Department of War has appointed Sonu Shankar as Principal Deputy Chief Information Officer.

Trellix has named David Pieterse as Chief Operating Officer GTM and David Soto as Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.