Safeware Glasswall APAC Partner
Book a demo

Explore

What is CDRZero TrustThe detection gapCapabilitiesUse cases

Products

ProductsIntegrationFile support

Compliance

Control alignmentAPAC regulatory landscape
Country guidesSingaporeAustraliaJapanSouth KoreaIndiaIndonesiaMalaysiaThailandVietnamPhilippinesTaiwanNew ZealandMongolia

More

Trust & certificationsInsightsPartnersAboutDocumentation Book a demo

Language

EnglishBahasa Indonesia日本語한국어Bahasa MelayuไทยTiếng Việt简体中文繁體中文

APAC breach record

When the breach arrived as a file

Publicly documented incidents across APAC where the initial access or payload delivery was a file: a weaponised document, a malicious attachment, an infected upload or transfer.

Validated events only. Every entry cites the public record, and every prevention statement is conditional analysis of the vector class, bounded by what Glasswall actually claims.

Coverage

33

documented events

8

territories

72

public sources cited

2014 to 2026

years spanned

Most recent

Latest documented events

The most recent file-borne events across the region. The full record is on the regional timeline.

  1. Phishing link in emailMedium impactAustralia

    GO2 Health: Phishing email opened a Brisbane clinic's main mailbox to an attacker

    The main reception mailbox at the Everton Park practice was accessed in April 2026. Because the mailbox auto archives, exposure was confined to twelve months of correspondence, which included some patients' Department of Veterans Affairs identification numbers, medical history and referrals; the primary patient records system was not reached. The regulator was notified in May and patients in July 2026, and no evidence of publication or misuse was reported.

    The documented vector. Phishing email that led to compromise of the practice's main mailbox. The practice's own statement says it became aware of unauthorised access to one of its email mailboxes via a phishing email, and engaged external experts to investigate and contain the incident. The statement does not specify what the message carried, and this entry does not fill that in.

    How this class of vector is removed

    The vector class the practice named, a phishing message reaching a shared clinical mailbox, crosses the boundary as a file. A CDR hop on inbound mail applies policy outcomes, warn, quarantine or block, and rebuilds carried content to its format's known good specification before it reaches a busy reception desk, which is a control that does not depend on the reader spotting the message. Glasswall does not claim to detect deceptive hyperlinks, so the mapping is held at low confidence where the statement does not say what the message carried.

    Email CDR RelayContent Disarm and ReconstructionGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • healthcare

    Source: ABC News · Source: Cyber Daily

  2. Phishing link in emailMedium impactNew Zealand

    Hutt City Council: A phishing email actioned by staff turned council mailboxes into an attack platform

    The March 2026 compromise was disclosed in a council report in April 2026. Five individuals had identity information compromised and 732 people may have had financial information exposed through email correspondence. The council reported the incident to the Office of the Privacy Commissioner and tightened security settings, monitoring and staff training; it declined a public records request for the full incident report.

    The documented vector. Phishing email actioned by a staff member, leading to takeover of several mailboxes. The council's incident report, as reported to its audit and risk subcommittee, records that the attack originated from a staff member responding to a phishing email, which gave attackers access to a small number of email accounts. Those accounts were then used to send further malicious email internally and externally.

    How this class of vector is removed

    This event shows the vector class propagating: once council mailboxes were sending, every recipient inside and outside the organisation received mail from a genuine government address. Rebuilding content to its format's known good specification and applying relay policy outcomes treats mail from a trusted internal sender exactly as it treats anything else, which is the property that matters once an account is speaking for the attacker. Glasswall does not claim to detect the deceptive link that began the chain, so the mapping is held at low confidence and rests on the file layer.

    Email CDR RelayContent Disarm and ReconstructionGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • government

    Source: 1News · Source: Cyber Daily

  3. Removable mediaMedium impactJapan

    Japan Ground Self-Defense Force: Counterfeit USB sticks carried malware onto more than 50 defence computers

    The devices were in use from April 2024 until the infection was confirmed in February 2025, and were connected to more than 50 computers, nearly half of them closed systems handling classified command and control information. Detection was accidental, after a soldier noticed a machine running slowly. The Ministry of Defense states the malware was limited to self propagation with no exfiltration or external communication, and no data loss has been confirmed. Procurement records were not retained, so the supply route is unestablished. The incident surfaced publicly in June 2026 and was answered in the Diet that July.

    The documented vector. Counterfeit USB memory devices carrying self propagating malware from manufacture. Answers to written questions in the House of Councillors record that internal rules were not observed and no computer virus scan was carried out to confirm the safety of the USB memory before use, and that the devices bore the name of a company located in China. Six sticks, sold as one terabyte but built from cheap microSD, were malware bearing at manufacture.

    How this class of vector is removed

    This class of vector, files arriving on removable media and crossing into a closed system, is the case cross domain transfer is built for: content moving between security domains is rebuilt to its format's known good specification at the crossing point rather than trusted because the medium was carried by hand, and the control is deployable in air gapped environments where no signature feed reaches. Foresight scores file structure without any outbound network call. The parliamentary answer records that the scan step required by internal rules was not performed, which is the control point this maps to.

    Cross-domain and air-gapped transferContent Disarm and ReconstructionForesight predictive file triageGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine / Glasswall Foresight

    • defence

    Source: House of Councillors, National Diet of Japan · Source: House of Councillors, National Diet of Japan

  4. Phishing link in emailHigh impactJapan

    Japanese online brokerages (Rakuten Securities, Nomura Securities, Daiwa Securities, SBI Securities and others): Phishing emails drove 19,000 account takeovers and hundreds of billions of yen in unauthorised trades

    From January 2025 the Financial Services Agency has published monthly counts of unauthorised access and unauthorised trading across Japanese online brokerages. To July 2026 the cumulative totals reached 19,142 unauthorised accesses and 10,607 unauthorised trades, with roughly 436.5 billion yen of sales and 383.5 billion yen of purchases executed in hijacked accounts; April 2025 alone accounted for 5,490 accesses. Eighteen firms were affected at the peak, most of which have agreed compensation schemes, and the Metropolitan Police made the first arrests in November 2025.

    The documented vector. Emails impersonating brokerages and their partners, carrying links to credential harvesting sites; infostealer malware also documented. The firms' own notices name the vector. Nomura describes cases where fake emails impersonating Nomura or its partners lure victims to phishing sites and steal account numbers and passwords. Daiwa describes emails and messages with a spoofed sender that make the recipient click an embedded link leading to a fake website. The Financial Services Agency describes customer information stolen through fake websites impersonating real securities firms.

    How this class of vector is removed

    The vector class here is the message itself, sent in volume and impersonating a trusted brand, so it crosses the boundary as a file whatever it carries. On the mail path the relay applies policy outcomes, allow, warn, quarantine or block, and deterministic rebuild strips active content from anything attached or subsequently delivered. Glasswall does not claim to detect deceptive hyperlinks, so where a campaign is purely a credential page reached from a message, this mapping addresses the file layer and not the link, and is held at low confidence accordingly.

    Email CDR RelayContent Disarm and ReconstructionGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • banking

    Source: Financial Services Agency · Source: Financial Services Agency · Source: Nomura Securities · Source: Daiwa Securities

  5. Phishing link in emailMedium impactJapan

    Casio Computer Co., Ltd.: Ransomware and data leak the company's report traced to phishing email defences

    Ransomware deployed on Casio's servers on 5 October 2024 by the group calling itself Underground leaked personal data of 8,478 employees, business partners and some customers, alongside internal documents. Casio published its final investigation report on 7 January 2025, identifying phishing email defence gaps as the entry route of a sophisticated attacker.

    The documented vector. Phishing email, per the company's final investigation report; mechanism not further specified. Casio's published final report on the incident attributes entry to gaps the investigation found in the company's phishing email countermeasures and global network security. The report frames the cause through the control rather than narrating the specific message, and this entry reflects that.

    How this class of vector is removed

    The vector class in the company's report, phishing email, crosses the trust boundary as a file: the message and anything it carries. A CDR hop on inbound mail applies policy outcomes, warn, quarantine or block, and rebuilds carried content to a known good specification without waiting on a detection verdict. Glasswall does not claim to detect deceptive hyperlinks, so the mapping is held at low confidence where the entry ran through a credential page rather than carried content.

    Email CDR RelayContent Disarm and ReconstructionGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • manufacturing

    Source: Casio Computer Co., Ltd. · Source: ASCII.jp

Coverage honesty

Territories not yet on this record

Some territories we track for compliance have no entry here. That is the inclusion bar working, not a gap in monitoring: each has suffered significant incidents, but no public record documents a file-borne vector for them, and we do not publish inferred vectors.

Indonesia. Indonesia has no data protection authority in operation yet, and the official chronology of its National Data Centre incident begins after the attacker was already inside, so the country's headline breaches are confirmed as events with their intrusion paths unpublished.

Malaysia. Mandatory breach notification only began in June 2025, the regulator's published enforcement list covers registration offences rather than breaches, and the CERT does not name victims, so a decision record that would document a vector does not yet exist.

Thailand. Thailand's data protection regulator has fined actively since 2024, but it describes respondents generically, as a technology retailer or a private hospital, and its orders address absent safeguards rather than attack methods, so no Thai event yet meets the naming and vector bar together.

Vietnam. Vietnam produces one half of the requirement or the other, never both: its best documented attachment campaigns, including the 2025 recruitment lure carrying a booby trapped archive, name no victim organisation, while its named victims have no published intrusion path even after a national investigation.

Mongolia. Mongolia's best documented incidents, the MonPass certificate authority and Able Desktop compromises, travelled through backdoored software distribution rather than a content channel, and the region's attachment campaigns name no individual victim organisation.

Method

What qualifies an event

Three tests, applied strictly, and events that fail any of them are excluded rather than stretched.

Validated. The event is documented by a regulator statement, an official inquiry or prosecutor report, the affected organisation's own disclosure, or reputable press with named confirmation. Every entry carries its sources.

File-borne. The public record documents that initial access or payload delivery travelled as a file: a malicious document or archive, a macro attachment, an infected upload or file transfer, removable media, or the email itself, since a message carrying malicious code or a deceptive hyperlink is a file crossing your boundary. Credential attacks and pure network exploits do not appear here.

Mappable. The vector belongs to a class of content that a named Glasswall capability processes. The analysis states how that class of vector is removed. It does not claim to know what the affected organisation ran, and it does not assign blame.

That third test excludes a whole category we could otherwise have listed. Invoice fraud, where a convincing message asks a finance team to change a supplier's bank details, arrives by email and is documented in police statements across the region. We leave it out, because a rebuilt document still carries the altered account number. Rebuilding files is not the control for that problem, and a record that implied otherwise would be worth less than a shorter honest one.

Scope

About these pages

Every event on this page meets three tests before it is published. It is documented by reliable public sources: a regulator, an official inquiry, the affected organisation's own disclosure, or reputable press with named confirmation, and each entry links to those sources. The initial access or payload delivery travelled as a file, as the public record states it. An email is itself a file, so malicious code in a message and deceptive-hyperlink phishing carried by a message both count; credential attacks and pure network exploits are excluded. And the prevention analysis is conditional: where we say a capability removes a class of vector, that is a statement about how the control treats that class of content, not a claim about what any organisation ran, and not a judgement on the people who dealt with the incident.

This page is a working reference, not an incident report or legal advice. Details reflect the public record on the review date and organisations named here are cited from that record alone.

The same vectors reach your boundary