File-borne breach events · East Asia
Japan: documented file-borne breach events
Japan has the region's richest documented record: eight events from the 2015 Japan Pension Service intrusion to the 2024 DMM Bitcoin theft and the KADOKAWA and Casio ransomware disclosures, most documented by official investigations or the affected organisations' own published reports.
Overview
What the record shows
Japan's public record is unusually good on this class of incident, for two reasons. Major breaches get official investigations: the Japan Pension Service intrusion of 2015 was examined by the ministry's verification committee, NISC and the Board of Audit of Japan, and the 2024 DMM Bitcoin theft was documented, vector included, in a joint statement by the FBI, the US Department of Defense Cyber Crime Center and Japan's National Police Agency. And Japanese organisations publish detailed incident reports under their own names: the University of Tokyo, KADOKAWA and Casio disclosures on this page each name the email vector themselves.
The events span the full file-borne spectrum: weaponised document attachments carrying remote access trojans, the 2022 Emotet wave's macro documents and password protected archives, targeted attack emails infecting staff machines, phishing messages that opened the door to ransomware, and a malicious script fetched from a link during a fake recruitment test. Where a Japanese headline incident is missing, its vector is not yet in the public record.
Documented events
File-borne incidents in Japan
Most recent first. Every entry cites the public record it is drawn from.
-
Japan Ground Self-Defense Force: Counterfeit USB sticks carried malware onto more than 50 defence computers
The devices were in use from April 2024 until the infection was confirmed in February 2025, and were connected to more than 50 computers, nearly half of them closed systems handling classified command and control information. Detection was accidental, after a soldier noticed a machine running slowly. The Ministry of Defense states the malware was limited to self propagation with no exfiltration or external communication, and no data loss has been confirmed. Procurement records were not retained, so the supply route is unestablished. The incident surfaced publicly in June 2026 and was answered in the Diet that July.
The documented vector. Counterfeit USB memory devices carrying self propagating malware from manufacture. Answers to written questions in the House of Councillors record that internal rules were not observed and no computer virus scan was carried out to confirm the safety of the USB memory before use, and that the devices bore the name of a company located in China. Six sticks, sold as one terabyte but built from cheap microSD, were malware bearing at manufacture.
How this class of vector is removed
This class of vector, files arriving on removable media and crossing into a closed system, is the case cross domain transfer is built for: content moving between security domains is rebuilt to its format's known good specification at the crossing point rather than trusted because the medium was carried by hand, and the control is deployable in air gapped environments where no signature feed reaches. Foresight scores file structure without any outbound network call. The parliamentary answer records that the scan step required by internal rules was not performed, which is the control point this maps to.
Cross-domain and air-gapped transferContent Disarm and ReconstructionForesight predictive file triageGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine / Glasswall Foresight
- defence
Source: House of Councillors, National Diet of Japan · Source: House of Councillors, National Diet of Japan
-
Japanese online brokerages (Rakuten Securities, Nomura Securities, Daiwa Securities, SBI Securities and others): Phishing emails drove 19,000 account takeovers and hundreds of billions of yen in unauthorised trades
From January 2025 the Financial Services Agency has published monthly counts of unauthorised access and unauthorised trading across Japanese online brokerages. To July 2026 the cumulative totals reached 19,142 unauthorised accesses and 10,607 unauthorised trades, with roughly 436.5 billion yen of sales and 383.5 billion yen of purchases executed in hijacked accounts; April 2025 alone accounted for 5,490 accesses. Eighteen firms were affected at the peak, most of which have agreed compensation schemes, and the Metropolitan Police made the first arrests in November 2025.
The documented vector. Emails impersonating brokerages and their partners, carrying links to credential harvesting sites; infostealer malware also documented. The firms' own notices name the vector. Nomura describes cases where fake emails impersonating Nomura or its partners lure victims to phishing sites and steal account numbers and passwords. Daiwa describes emails and messages with a spoofed sender that make the recipient click an embedded link leading to a fake website. The Financial Services Agency describes customer information stolen through fake websites impersonating real securities firms.
How this class of vector is removed
The vector class here is the message itself, sent in volume and impersonating a trusted brand, so it crosses the boundary as a file whatever it carries. On the mail path the relay applies policy outcomes, allow, warn, quarantine or block, and deterministic rebuild strips active content from anything attached or subsequently delivered. Glasswall does not claim to detect deceptive hyperlinks, so where a campaign is purely a credential page reached from a message, this mapping addresses the file layer and not the link, and is held at low confidence accordingly.
Email CDR RelayContent Disarm and ReconstructionGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine
- banking
Source: Financial Services Agency · Source: Financial Services Agency · Source: Nomura Securities · Source: Daiwa Securities
-
Casio Computer Co., Ltd.: Ransomware and data leak the company's report traced to phishing email defences
Ransomware deployed on Casio's servers on 5 October 2024 by the group calling itself Underground leaked personal data of 8,478 employees, business partners and some customers, alongside internal documents. Casio published its final investigation report on 7 January 2025, identifying phishing email defence gaps as the entry route of a sophisticated attacker.
The documented vector. Phishing email, per the company's final investigation report; mechanism not further specified. Casio's published final report on the incident attributes entry to gaps the investigation found in the company's phishing email countermeasures and global network security. The report frames the cause through the control rather than narrating the specific message, and this entry reflects that.
How this class of vector is removed
The vector class in the company's report, phishing email, crosses the trust boundary as a file: the message and anything it carries. A CDR hop on inbound mail applies policy outcomes, warn, quarantine or block, and rebuilds carried content to a known good specification without waiting on a detection verdict. Glasswall does not claim to detect deceptive hyperlinks, so the mapping is held at low confidence where the entry ran through a credential page rather than carried content.
Email CDR RelayContent Disarm and ReconstructionGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine
- manufacturing
-
Japan Radio Co., Ltd.: One credential entry turned a supplier's account into 994 attack emails to customers
After the account was taken over, 994 attack emails were sent to Japan Radio's customer addresses on 1 October 2024. The final report of February 2025 confirmed leakage of personal data for the company, its group companies, distributors and business partners, including names, telephone and fax numbers and email addresses, alongside product pricing and contract details. No payment card data was involved.
The documented vector. Email impersonating a business partner, carrying a URL that led to credential entry. The company's published investigation findings state that on 24 September the employee accessed a URL contained in an email from a business partner and entered their identifier and password, so their sign-in information was stolen. The hijacked account was then used to send targeted attack mail onward.
How this class of vector is removed
This event shows the vector class travelling in both directions, and the second direction is the one a file control answers squarely: 994 messages reached customers from a genuine supplier address, where sender trust offered the recipients nothing. Rebuilding inbound content to its format's known good specification and applying relay policy outcomes treats mail from a trusted partner exactly as it treats any other. Glasswall does not claim to detect the deceptive link that started the chain, so the mapping is held at medium confidence and rests on the file layer.
Email CDR RelayContent Disarm and ReconstructionGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine
- manufacturing
-
KADOKAWA Corporation: Niconico and group systems taken down by ransomware rooted in phishing
A ransomware attack detected on 8 June 2024 took down the Niconico video platform and much of the KADOKAWA group's infrastructure for months, with the personal data of 254,241 people affected. The company's August 2024 disclosure presumes entry came from phishing based credential theft from an employee account, and the BlackSuit group claimed the attack.
The documented vector. Phishing attack against an employee account, the company's stated root cause; mechanism not further specified. KADOKAWA's own disclosure, based on an external forensic investigation, states that employee account information being stolen through phishing and similar attacks is presumed to be the root cause of the incident, while noting that the specific pathway and method remain unknown. This entry carries that qualification rather than firming it up.
How this class of vector is removed
The vector class the company named, a phishing message reaching an employee, crosses the boundary as a file: the email itself. On the mail path the relay applies policy outcomes, warn, quarantine or block, to inbound mail, and deterministic rebuild strips active content from whatever a message carries. Glasswall does not claim to detect deceptive hyperlinks, so where the theft ran through a credential page rather than carried content, the mapping is held at low confidence and says so.
Email CDR RelayContent Disarm and ReconstructionGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine
- media
-
DMM Bitcoin (via wallet provider Ginco Inc.): 4,502 BTC stolen after a malicious script posed as a recruitment test
After the March 2024 compromise of a Ginco employee, the attackers used stolen session information to impersonate the employee and manipulate a legitimate transaction, stealing 4,502.9 bitcoin worth about 308 million US dollars from DMM Bitcoin in May 2024. The exchange later wound down its business. The December 2024 joint statement by the FBI, DC3 and Japan's National Police Agency attributed the theft to the TraderTraitor group.
The documented vector. Malicious Python script fetched from a GitHub link, posed as a pre employment test. A North Korean actor posing as a recruiter on LinkedIn sent an employee of Ginco, the wallet software provider for DMM Bitcoin, a URL linking to a malicious Python script under the guise of a pre employment test. The vector is stated verbatim in the joint attribution by the FBI, the US Department of Defense Cyber Crime Center and Japan's National Police Agency.
How this class of vector is removed
This class of vector, an executable script fetched over the web under a social pretext, is addressed at the download boundary rather than in the inbox: an ICAP hop routes web downloads through the CDR pipeline, where policy acts on every file and content that cannot be rebuilt to a known good specification, such as raw script files, can be quarantined or blocked rather than delivered. Foresight adds a structural triage score ahead of that decision. The mapping is held at medium confidence because a script is policy handled rather than rebuilt, and the lure arrived outside the corporate mail path.
ICAP ClientForesight predictive file triageGlasswall Halo / Glasswall Foresight
- banking
Source: FBI, DC3 and National Police Agency of Japan · Source: BleepingComputer · Source: Wiz Research
-
University of Tokyo, Graduate School of Arts and Sciences: Targeted attack email infected a professor's machine, exposing 4,000 records
A professor's PC at the Graduate School of Arts and Sciences on the Komaba campus was infected via a targeted attack email in July 2022, with roughly 4,000 records on students, staff, alumni and academic society members potentially exfiltrated. The university disclosed the incident in October 2023 after investigation.
The documented vector. Targeted attack email carrying malware; the university's disclosure names the email as the infection route. The university's disclosure states that a faculty member's work from home PC was infected with malware by a targeted attack email received on 19 July 2022, with the lure styled as a lecture or interview request. The disclosure names the email as the route without separating attachment from link, and this entry carries that wording.
How this class of vector is removed
This class of vector, a targeted email delivering malware to one chosen recipient, is exactly where detection struggles and deterministic controls hold: content carried by inbound mail is rebuilt to its format's known good specification with active content stripped, whatever the lure, and policy outcomes apply to the message itself. Foresight scores anomalous file construction before anything runs. The mapping is held at medium confidence because the disclosure does not separate attachment from link.
Content Disarm and ReconstructionEmail CDR RelayForesight predictive file triageGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine / Glasswall Foresight
- education
-
University of Tokyo, Institute for Future Initiatives: A second targeted attack email at the same university leaked 207 people's data
A targeted attack email infected a PC at the University of Tokyo's Institute for Future Initiatives in July 2022, leaking data on 207 people. Together with the Komaba incident the same month, the record shows a sustained email borne campaign against the university.
The documented vector. Targeted attack email carrying malware; the institute's notice names the email as the infection route. The institute's official notice states a staff PC was infected with malware by a targeted attack email received in mid July 2022. Leakage was confirmed in January 2023, covering personal data including bank account details held in administrative documents.
How this class of vector is removed
The same class of vector as the Komaba incident, a targeted email carrying malware to a specific recipient, is removed at the mail boundary: carried content is rebuilt to the format's known good specification before delivery, policy outcomes apply to the message, and Foresight scores structural anomalies ahead of the pipeline. Held at medium confidence because the notice does not separate attachment from link.
Content Disarm and ReconstructionEmail CDR RelayForesight predictive file triageGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine / Glasswall Foresight
- education
Source: University of Tokyo, Institute for Future Initiatives · Source: Mynavi News
-
RIKEN: Japan's largest research institute infected in the Emotet wave, then impersonated in spoofed mail
RIKEN, Japan's largest comprehensive research institution, confirmed in March 2022 that it had been infected with Emotet, after which emails impersonating its staff, using real names and departments, were sent to outside contacts. The institute issued a public warning about the spoofed mail and its attachments.
The documented vector. Emotet emails carrying zip archives and macro bearing files. RIKEN confirmed an Emotet infection during the March 2022 wave and warned that the spoofed messages sent in its name carried zip files and macro bearing files. Japan's Information technology Promotion Agency documented the same wave as driven by malicious Excel macro attachments.
How this class of vector is removed
This class of vector, macro bearing Office files and archives arriving by email, is removed by deterministic CDR rebuild: the document is reconstructed to its format's known good specification and the macro is not carried into the rebuilt file, while macro intelligence inspects embedded active content for the policy decision. The Email CDR Relay puts that rebuild on inbound mail, so the control does not wait for a signature covering that week's Emotet build.
Content Disarm and ReconstructionMacro intelligenceEmail CDR RelayGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine
- research
Source: ScanNetSecurity · Source: Information technology Promotion Agency (IPA)
-
Kracie Holdings, Ltd.: Emotet reached a consumer goods maker through an encrypted attachment
Kracie Holdings disclosed in February 2022 that an Emotet infection had leaked email addresses and led to impersonation emails being sent to its contacts. The infection route was confirmed in the same Nikkei xTECH survey of the disclosing companies.
The documented vector. Encrypted (password protected) file attached to email, carrying Emotet. Nikkei xTECH's survey records Kracie's infection route as an encrypted file attached to an email, the same technique used across the February 2022 wave to carry the payload past inline inspection.
How this class of vector is removed
This class of vector, malware packed inside a password protected attachment, is removed by treating the encrypted file as unreadable rather than as trusted: it is held, released to the legitimate recipient, and rebuilt to the format's known good specification once decrypted, so the delivered document is reconstructed rather than merely scanned and passed.
Content Disarm and ReconstructionEmail CDR RelayQuarantineGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine
- manufacturing
-
Wacoal Corp.: Encrypted email attachment carried Emotet into the apparel maker's network
Wacoal disclosed in February 2022 that an employee PC had been infected with Emotet, leading to theft of email information and spoofed messages sent to its contacts. It was one of the companies whose infection route Nikkei xTECH confirmed directly with the organisation.
The documented vector. Encrypted (password protected) file attached to email, carrying Emotet. Nikkei xTECH's survey of the disclosing companies records Wacoal's infection route as an encrypted file attached to an email. The password protection is the point of the technique: it defeats inline inspection of the attachment in transit.
How this class of vector is removed
The same class of vector as the other disclosures in this wave, an encrypted attachment whose contents no gateway scanner can read in transit, is handled by holding the file and rebuilding it at release: the recipient supplies the password, CDR reconstructs the document to its format's known good specification, and what lands on the desktop no longer carries the loader.
Content Disarm and ReconstructionEmail CDR RelayQuarantineGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine
- manufacturing
-
Lion Corporation: Emotet arrived as an encrypted email attachment, leaking mail data and spawning impersonation emails
Lion Corporation disclosed on 3 February 2022 that an employee PC had been infected with Emotet, leaking email addresses and mail data from its mail environment and triggering waves of impersonation emails to customers and partners. The company published a notice the following day.
The documented vector. Encrypted (password protected) file attached to email, carrying Emotet. Nikkei xTECH surveyed the companies that disclosed Emotet infections in the January and February 2022 wave and established each one's infection route. Lion's route was an encrypted file attached to an email, the password protected pattern that puts a payload beyond inline scanning, which JPCERT/CC documented across the same wave.
How this class of vector is removed
This class of vector, a password protected attachment carrying commodity malware, is the case inline scanning cannot resolve: the file arrives as opaque ciphertext. Quarantine holds it and releases a rebuilt copy once the legitimate recipient supplies the password, so the document reaches the user reconstructed to its format's known good specification rather than as the attacker packed it, with the Email CDR Relay applying that rebuild across inbound mail.
Content Disarm and ReconstructionEmail CDR RelayQuarantineGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine
- manufacturing
Source: Lion Corporation · Source: Nikkei xTECH · Source: JPCERT/CC
-
Sekisui House, Ltd.: Emotet reached the housing group through a URL in the body of an email
Sekisui House disclosed an Emotet infection in January 2022 that harvested email data and led to impersonation emails being sent to its contacts. Nikkei xTECH established the infection route for each disclosing company in the wave, and the group later moved away from password protected attachment practices.
The documented vector. URL in the email body, leading to the Emotet payload. Nikkei xTECH's survey of the disclosing companies records Sekisui House's infection route as a URL in the body of an email, rather than an attachment. The same wave used both routes, which is why this record distinguishes them.
How this class of vector is removed
This class of vector puts the payload one step behind the message, so the control sits at the fetch rather than the inbox: an ICAP hop routes the resulting web download through CDR, rebuilding the delivered file to its format's known good specification before it reaches the desktop, while the mail relay applies policy outcomes to the message itself. Glasswall does not claim to detect deceptive hyperlinks, so this mapping addresses what the link delivers, not the link.
ICAP ClientContent Disarm and ReconstructionEmail CDR RelayGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine
- construction
-
JTB Corp.: 7.93 million customer records exposed after a booking-document lure installed PlugX
JTB disclosed on 14 June 2016 that personal data of about 7.93 million customers had been exposed, including names, addresses, email addresses and more than 4,300 valid passport numbers. The intrusion began in March 2016 when an employee opened a malicious email attachment, installing PlugX; Japanese police investigated the incident.
The documented vector. Malicious document attachment posing as an airline booking document, delivering the PlugX remote access trojan. An employee of JTB subsidiary i.JTB opened a targeted email attachment disguised as an airline booking document. Opening the file installed the PlugX remote access trojan, from which the attackers reached the server holding customer booking data. The attachment vector is consistently documented across threat intelligence and contemporaneous press reporting of JTB's disclosure.
How this class of vector is removed
This class of vector, a weaponised document lure carrying a remote access trojan, is removed by deterministic CDR rebuild: the attachment is rebuilt against the format specification and active content is stripped, so the document that reaches the employee no longer carries the loader, whatever the lure looks like. The Email CDR Relay places that rebuild on inbound mail before delivery.
Content Disarm and ReconstructionEmail CDR RelayGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine
- travel
-
Japan Pension Service: 1.25 million pension records exfiltrated after staff opened malicious email attachments
Staff at the Japan Pension Service opened malware-laden email attachments in May 2015, giving attackers a foothold on the internal network. Roughly 1.25 million records, including basic pension numbers and names covering about 1.01 million people, were exfiltrated between 21 and 23 May 2015. The service disclosed the breach on 1 June 2015, and official verification reports followed from the ministry's committee, NISC and the Board of Audit of Japan.
The documented vector. Malicious file attachments carrying the Emdivi remote access trojan. Targeted emails carrying attachments that contained malicious programs were sent to Japan Pension Service staff, and the infection began when staff opened those attachments. The Board of Audit of Japan's report documents the attachment delivery, and JPCERT/CC identified the malware as the Emdivi family used in the Blue Termite campaign of targeted attacks on Japanese organisations.
How this class of vector is removed
This class of vector, a malicious document arriving as an email attachment, is removed by deterministic CDR rebuild: every inbound attachment is rebuilt to its format's known-good specification, stripping macros, embedded objects and other active content without depending on a detection verdict, which matters when the payload is a targeted trojan no signature yet describes. On the mail path, the Email CDR Relay applies that rebuild before delivery, and Foresight can score the attachment's structure ahead of the pipeline to flag anomalous construction before anything runs.
Content Disarm and ReconstructionEmail CDR RelayForesight predictive file triageGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine / Glasswall Foresight
- government
Source: Board of Audit of Japan · Source: JPCERT/CC · Source: The Japan Times
Scope
How to read this page
Every event on this page meets three tests before it is published. It is documented by reliable public sources: a regulator, an official inquiry, the affected organisation's own disclosure, or reputable press with named confirmation, and each entry links to those sources. The initial access or payload delivery travelled as a file, as the public record states it. An email is itself a file, so malicious code in a message and deceptive-hyperlink phishing carried by a message both count; credential attacks and pure network exploits are excluded. And the prevention analysis is conditional: where we say a capability removes a class of vector, that is a statement about how the control treats that class of content, not a claim about what any organisation ran, and not a judgement on the people who dealt with the incident.
This page is a working reference, not an incident report or legal advice. Details reflect the public record on the review date and organisations named here are cited from that record alone.
Elsewhere in the region

