APAC breach record
When the breach arrived as a file
Publicly documented incidents across APAC where the initial access or payload delivery was a file: a weaponised document, a malicious attachment, an infected upload or transfer.
Validated events only. Every entry cites the public record, and every prevention statement is conditional analysis of the vector class, bounded by what Glasswall actually claims.
Coverage
33
documented events
8
territories
72
public sources cited
2014 to 2026
years spanned
Most recent
Latest documented events
The most recent file-borne events across the region. The full record is on the regional timeline.
-
GO2 Health: Phishing email opened a Brisbane clinic's main mailbox to an attacker
The main reception mailbox at the Everton Park practice was accessed in April 2026. Because the mailbox auto archives, exposure was confined to twelve months of correspondence, which included some patients' Department of Veterans Affairs identification numbers, medical history and referrals; the primary patient records system was not reached. The regulator was notified in May and patients in July 2026, and no evidence of publication or misuse was reported.
The documented vector. Phishing email that led to compromise of the practice's main mailbox. The practice's own statement says it became aware of unauthorised access to one of its email mailboxes via a phishing email, and engaged external experts to investigate and contain the incident. The statement does not specify what the message carried, and this entry does not fill that in.
How this class of vector is removed
The vector class the practice named, a phishing message reaching a shared clinical mailbox, crosses the boundary as a file. A CDR hop on inbound mail applies policy outcomes, warn, quarantine or block, and rebuilds carried content to its format's known good specification before it reaches a busy reception desk, which is a control that does not depend on the reader spotting the message. Glasswall does not claim to detect deceptive hyperlinks, so the mapping is held at low confidence where the statement does not say what the message carried.
Email CDR RelayContent Disarm and ReconstructionGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine
- healthcare
-
Hutt City Council: A phishing email actioned by staff turned council mailboxes into an attack platform
The March 2026 compromise was disclosed in a council report in April 2026. Five individuals had identity information compromised and 732 people may have had financial information exposed through email correspondence. The council reported the incident to the Office of the Privacy Commissioner and tightened security settings, monitoring and staff training; it declined a public records request for the full incident report.
The documented vector. Phishing email actioned by a staff member, leading to takeover of several mailboxes. The council's incident report, as reported to its audit and risk subcommittee, records that the attack originated from a staff member responding to a phishing email, which gave attackers access to a small number of email accounts. Those accounts were then used to send further malicious email internally and externally.
How this class of vector is removed
This event shows the vector class propagating: once council mailboxes were sending, every recipient inside and outside the organisation received mail from a genuine government address. Rebuilding content to its format's known good specification and applying relay policy outcomes treats mail from a trusted internal sender exactly as it treats anything else, which is the property that matters once an account is speaking for the attacker. Glasswall does not claim to detect the deceptive link that began the chain, so the mapping is held at low confidence and rests on the file layer.
Email CDR RelayContent Disarm and ReconstructionGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine
- government
-
Japan Ground Self-Defense Force: Counterfeit USB sticks carried malware onto more than 50 defence computers
The devices were in use from April 2024 until the infection was confirmed in February 2025, and were connected to more than 50 computers, nearly half of them closed systems handling classified command and control information. Detection was accidental, after a soldier noticed a machine running slowly. The Ministry of Defense states the malware was limited to self propagation with no exfiltration or external communication, and no data loss has been confirmed. Procurement records were not retained, so the supply route is unestablished. The incident surfaced publicly in June 2026 and was answered in the Diet that July.
The documented vector. Counterfeit USB memory devices carrying self propagating malware from manufacture. Answers to written questions in the House of Councillors record that internal rules were not observed and no computer virus scan was carried out to confirm the safety of the USB memory before use, and that the devices bore the name of a company located in China. Six sticks, sold as one terabyte but built from cheap microSD, were malware bearing at manufacture.
How this class of vector is removed
This class of vector, files arriving on removable media and crossing into a closed system, is the case cross domain transfer is built for: content moving between security domains is rebuilt to its format's known good specification at the crossing point rather than trusted because the medium was carried by hand, and the control is deployable in air gapped environments where no signature feed reaches. Foresight scores file structure without any outbound network call. The parliamentary answer records that the scan step required by internal rules was not performed, which is the control point this maps to.
Cross-domain and air-gapped transferContent Disarm and ReconstructionForesight predictive file triageGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine / Glasswall Foresight
- defence
Source: House of Councillors, National Diet of Japan · Source: House of Councillors, National Diet of Japan
-
Japanese online brokerages (Rakuten Securities, Nomura Securities, Daiwa Securities, SBI Securities and others): Phishing emails drove 19,000 account takeovers and hundreds of billions of yen in unauthorised trades
From January 2025 the Financial Services Agency has published monthly counts of unauthorised access and unauthorised trading across Japanese online brokerages. To July 2026 the cumulative totals reached 19,142 unauthorised accesses and 10,607 unauthorised trades, with roughly 436.5 billion yen of sales and 383.5 billion yen of purchases executed in hijacked accounts; April 2025 alone accounted for 5,490 accesses. Eighteen firms were affected at the peak, most of which have agreed compensation schemes, and the Metropolitan Police made the first arrests in November 2025.
The documented vector. Emails impersonating brokerages and their partners, carrying links to credential harvesting sites; infostealer malware also documented. The firms' own notices name the vector. Nomura describes cases where fake emails impersonating Nomura or its partners lure victims to phishing sites and steal account numbers and passwords. Daiwa describes emails and messages with a spoofed sender that make the recipient click an embedded link leading to a fake website. The Financial Services Agency describes customer information stolen through fake websites impersonating real securities firms.
How this class of vector is removed
The vector class here is the message itself, sent in volume and impersonating a trusted brand, so it crosses the boundary as a file whatever it carries. On the mail path the relay applies policy outcomes, allow, warn, quarantine or block, and deterministic rebuild strips active content from anything attached or subsequently delivered. Glasswall does not claim to detect deceptive hyperlinks, so where a campaign is purely a credential page reached from a message, this mapping addresses the file layer and not the link, and is held at low confidence accordingly.
Email CDR RelayContent Disarm and ReconstructionGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine
- banking
Source: Financial Services Agency · Source: Financial Services Agency · Source: Nomura Securities · Source: Daiwa Securities
-
Casio Computer Co., Ltd.: Ransomware and data leak the company's report traced to phishing email defences
Ransomware deployed on Casio's servers on 5 October 2024 by the group calling itself Underground leaked personal data of 8,478 employees, business partners and some customers, alongside internal documents. Casio published its final investigation report on 7 January 2025, identifying phishing email defence gaps as the entry route of a sophisticated attacker.
The documented vector. Phishing email, per the company's final investigation report; mechanism not further specified. Casio's published final report on the incident attributes entry to gaps the investigation found in the company's phishing email countermeasures and global network security. The report frames the cause through the control rather than narrating the specific message, and this entry reflects that.
How this class of vector is removed
The vector class in the company's report, phishing email, crosses the trust boundary as a file: the message and anything it carries. A CDR hop on inbound mail applies policy outcomes, warn, quarantine or block, and rebuilds carried content to a known good specification without waiting on a detection verdict. Glasswall does not claim to detect deceptive hyperlinks, so the mapping is held at low confidence where the entry ran through a credential page rather than carried content.
Email CDR RelayContent Disarm and ReconstructionGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine
- manufacturing
Southeast Asia
Southeast Asia territories
2 documented events
Philippines
The Philippine privacy regulator publishes resolutions that name the mechanism, and two of them document files: malicious Excel attachments that opened a cruise operator's network, and a credential harvesting file mailed to 387 recipients.
2 documented events
Singapore
Singapore's record pairs the country's largest breach, SingHealth, whose Committee of Inquiry traced entry to a phishing email carrying malicious code, with the 2019 ST Logistics incident, where the regulator's published decision names the exact malicious .doc attachment.
Oceania
Oceania territories
5 documented events
Australia
Australia documents breach vectors in court rather than in press releases: the regulators' filings against FIIG Securities, RI Advice and Australian Clinical Labs each name the file or the email, and the university at the centre of the 2018 ANU breach published its own attack chain.
2 documented events
New Zealand
New Zealand's largest health-sector cyber attack, the 2021 Waikato District Health Board ransomware incident, was publicly attributed by the board itself to an email attachment as the initial incursion.
East Asia
East Asia territories
15 documented events
Japan
Japan has the region's richest documented record: eight events from the 2015 Japan Pension Service intrusion to the 2024 DMM Bitcoin theft and the KADOKAWA and Casio ransomware disclosures, most documented by official investigations or the affected organisations' own published reports.
4 documented events
South Korea
Korea's record runs from prosecutor-documented weaponised HWP documents at a nuclear operator to the privacy regulator's recent penalties over malicious files uploaded straight through web upload functions, including a decision issued in August 2026.
2 documented events
Taiwan
Taiwan's record runs from the 2016 First Commercial Bank ATM heist, traced by investigators to a spear-phishing email, to D-Link's own 2023 confirmation that a phished employee was the route into its systems.
Coverage honesty
Territories not yet on this record
Some territories we track for compliance have no entry here. That is the inclusion bar working, not a gap in monitoring: each has suffered significant incidents, but no public record documents a file-borne vector for them, and we do not publish inferred vectors.
Indonesia. Indonesia has no data protection authority in operation yet, and the official chronology of its National Data Centre incident begins after the attacker was already inside, so the country's headline breaches are confirmed as events with their intrusion paths unpublished.
Malaysia. Mandatory breach notification only began in June 2025, the regulator's published enforcement list covers registration offences rather than breaches, and the CERT does not name victims, so a decision record that would document a vector does not yet exist.
Thailand. Thailand's data protection regulator has fined actively since 2024, but it describes respondents generically, as a technology retailer or a private hospital, and its orders address absent safeguards rather than attack methods, so no Thai event yet meets the naming and vector bar together.
Vietnam. Vietnam produces one half of the requirement or the other, never both: its best documented attachment campaigns, including the 2025 recruitment lure carrying a booby trapped archive, name no victim organisation, while its named victims have no published intrusion path even after a national investigation.
Mongolia. Mongolia's best documented incidents, the MonPass certificate authority and Able Desktop compromises, travelled through backdoored software distribution rather than a content channel, and the region's attachment campaigns name no individual victim organisation.
Method
What qualifies an event
Three tests, applied strictly, and events that fail any of them are excluded rather than stretched.
Validated. The event is documented by a regulator statement, an official inquiry or prosecutor report, the affected organisation's own disclosure, or reputable press with named confirmation. Every entry carries its sources.
File-borne. The public record documents that initial access or payload delivery travelled as a file: a malicious document or archive, a macro attachment, an infected upload or file transfer, removable media, or the email itself, since a message carrying malicious code or a deceptive hyperlink is a file crossing your boundary. Credential attacks and pure network exploits do not appear here.
Mappable. The vector belongs to a class of content that a named Glasswall capability processes. The analysis states how that class of vector is removed. It does not claim to know what the affected organisation ran, and it does not assign blame.
That third test excludes a whole category we could otherwise have listed. Invoice fraud, where a convincing message asks a finance team to change a supplier's bank details, arrives by email and is documented in police statements across the region. We leave it out, because a rebuilt document still carries the altered account number. Rebuilding files is not the control for that problem, and a record that implied otherwise would be worth less than a shorter honest one.
Scope
About these pages
Every event on this page meets three tests before it is published. It is documented by reliable public sources: a regulator, an official inquiry, the affected organisation's own disclosure, or reputable press with named confirmation, and each entry links to those sources. The initial access or payload delivery travelled as a file, as the public record states it. An email is itself a file, so malicious code in a message and deceptive-hyperlink phishing carried by a message both count; credential attacks and pure network exploits are excluded. And the prevention analysis is conditional: where we say a capability removes a class of vector, that is a statement about how the control treats that class of content, not a claim about what any organisation ran, and not a judgement on the people who dealt with the incident.
This page is a working reference, not an incident report or legal advice. Details reflect the public record on the review date and organisations named here are cited from that record alone.

