Safeware Glasswall APAC Partner
Book a demo

Explore

What is CDRZero TrustThe detection gapCapabilitiesUse cases

Products

ProductsIntegrationFile support

Compliance

Control alignmentAPAC regulatory landscape
Country guidesSingaporeAustraliaJapanSouth KoreaIndiaIndonesiaMalaysiaThailandVietnamPhilippinesTaiwanNew ZealandMongolia

More

Trust & certificationsInsightsPartnersAboutDocumentation Book a demo

Language

EnglishBahasa Indonesia日本語한국어Bahasa MelayuไทยTiếng Việt简体中文繁體中文

Regional timeline

APAC file-borne breaches, in order

The full validated record, most recent first. Each entry names the territory, the documented vector and the sources it is drawn from.

The record

Documented file-borne events

Most recent first. Every entry cites the public record it is drawn from.

  1. Phishing link in emailMedium impactAustralia

    GO2 Health: Phishing email opened a Brisbane clinic's main mailbox to an attacker

    The main reception mailbox at the Everton Park practice was accessed in April 2026. Because the mailbox auto archives, exposure was confined to twelve months of correspondence, which included some patients' Department of Veterans Affairs identification numbers, medical history and referrals; the primary patient records system was not reached. The regulator was notified in May and patients in July 2026, and no evidence of publication or misuse was reported.

    The documented vector. Phishing email that led to compromise of the practice's main mailbox. The practice's own statement says it became aware of unauthorised access to one of its email mailboxes via a phishing email, and engaged external experts to investigate and contain the incident. The statement does not specify what the message carried, and this entry does not fill that in.

    How this class of vector is removed

    The vector class the practice named, a phishing message reaching a shared clinical mailbox, crosses the boundary as a file. A CDR hop on inbound mail applies policy outcomes, warn, quarantine or block, and rebuilds carried content to its format's known good specification before it reaches a busy reception desk, which is a control that does not depend on the reader spotting the message. Glasswall does not claim to detect deceptive hyperlinks, so the mapping is held at low confidence where the statement does not say what the message carried.

    Email CDR RelayContent Disarm and ReconstructionGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • healthcare

    Source: ABC News · Source: Cyber Daily

  2. Phishing link in emailMedium impactNew Zealand

    Hutt City Council: A phishing email actioned by staff turned council mailboxes into an attack platform

    The March 2026 compromise was disclosed in a council report in April 2026. Five individuals had identity information compromised and 732 people may have had financial information exposed through email correspondence. The council reported the incident to the Office of the Privacy Commissioner and tightened security settings, monitoring and staff training; it declined a public records request for the full incident report.

    The documented vector. Phishing email actioned by a staff member, leading to takeover of several mailboxes. The council's incident report, as reported to its audit and risk subcommittee, records that the attack originated from a staff member responding to a phishing email, which gave attackers access to a small number of email accounts. Those accounts were then used to send further malicious email internally and externally.

    How this class of vector is removed

    This event shows the vector class propagating: once council mailboxes were sending, every recipient inside and outside the organisation received mail from a genuine government address. Rebuilding content to its format's known good specification and applying relay policy outcomes treats mail from a trusted internal sender exactly as it treats anything else, which is the property that matters once an account is speaking for the attacker. Glasswall does not claim to detect the deceptive link that began the chain, so the mapping is held at low confidence and rests on the file layer.

    Email CDR RelayContent Disarm and ReconstructionGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • government

    Source: 1News · Source: Cyber Daily

  3. Removable mediaMedium impactJapan

    Japan Ground Self-Defense Force: Counterfeit USB sticks carried malware onto more than 50 defence computers

    The devices were in use from April 2024 until the infection was confirmed in February 2025, and were connected to more than 50 computers, nearly half of them closed systems handling classified command and control information. Detection was accidental, after a soldier noticed a machine running slowly. The Ministry of Defense states the malware was limited to self propagation with no exfiltration or external communication, and no data loss has been confirmed. Procurement records were not retained, so the supply route is unestablished. The incident surfaced publicly in June 2026 and was answered in the Diet that July.

    The documented vector. Counterfeit USB memory devices carrying self propagating malware from manufacture. Answers to written questions in the House of Councillors record that internal rules were not observed and no computer virus scan was carried out to confirm the safety of the USB memory before use, and that the devices bore the name of a company located in China. Six sticks, sold as one terabyte but built from cheap microSD, were malware bearing at manufacture.

    How this class of vector is removed

    This class of vector, files arriving on removable media and crossing into a closed system, is the case cross domain transfer is built for: content moving between security domains is rebuilt to its format's known good specification at the crossing point rather than trusted because the medium was carried by hand, and the control is deployable in air gapped environments where no signature feed reaches. Foresight scores file structure without any outbound network call. The parliamentary answer records that the scan step required by internal rules was not performed, which is the control point this maps to.

    Cross-domain and air-gapped transferContent Disarm and ReconstructionForesight predictive file triageGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine / Glasswall Foresight

    • defence

    Source: House of Councillors, National Diet of Japan · Source: House of Councillors, National Diet of Japan

  4. Phishing link in emailHigh impactJapan

    Japanese online brokerages (Rakuten Securities, Nomura Securities, Daiwa Securities, SBI Securities and others): Phishing emails drove 19,000 account takeovers and hundreds of billions of yen in unauthorised trades

    From January 2025 the Financial Services Agency has published monthly counts of unauthorised access and unauthorised trading across Japanese online brokerages. To July 2026 the cumulative totals reached 19,142 unauthorised accesses and 10,607 unauthorised trades, with roughly 436.5 billion yen of sales and 383.5 billion yen of purchases executed in hijacked accounts; April 2025 alone accounted for 5,490 accesses. Eighteen firms were affected at the peak, most of which have agreed compensation schemes, and the Metropolitan Police made the first arrests in November 2025.

    The documented vector. Emails impersonating brokerages and their partners, carrying links to credential harvesting sites; infostealer malware also documented. The firms' own notices name the vector. Nomura describes cases where fake emails impersonating Nomura or its partners lure victims to phishing sites and steal account numbers and passwords. Daiwa describes emails and messages with a spoofed sender that make the recipient click an embedded link leading to a fake website. The Financial Services Agency describes customer information stolen through fake websites impersonating real securities firms.

    How this class of vector is removed

    The vector class here is the message itself, sent in volume and impersonating a trusted brand, so it crosses the boundary as a file whatever it carries. On the mail path the relay applies policy outcomes, allow, warn, quarantine or block, and deterministic rebuild strips active content from anything attached or subsequently delivered. Glasswall does not claim to detect deceptive hyperlinks, so where a campaign is purely a credential page reached from a message, this mapping addresses the file layer and not the link, and is held at low confidence accordingly.

    Email CDR RelayContent Disarm and ReconstructionGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • banking

    Source: Financial Services Agency · Source: Financial Services Agency · Source: Nomura Securities · Source: Daiwa Securities

  5. Phishing link in emailMedium impactJapan

    Casio Computer Co., Ltd.: Ransomware and data leak the company's report traced to phishing email defences

    Ransomware deployed on Casio's servers on 5 October 2024 by the group calling itself Underground leaked personal data of 8,478 employees, business partners and some customers, alongside internal documents. Casio published its final investigation report on 7 January 2025, identifying phishing email defence gaps as the entry route of a sophisticated attacker.

    The documented vector. Phishing email, per the company's final investigation report; mechanism not further specified. Casio's published final report on the incident attributes entry to gaps the investigation found in the company's phishing email countermeasures and global network security. The report frames the cause through the control rather than narrating the specific message, and this entry reflects that.

    How this class of vector is removed

    The vector class in the company's report, phishing email, crosses the trust boundary as a file: the message and anything it carries. A CDR hop on inbound mail applies policy outcomes, warn, quarantine or block, and rebuilds carried content to a known good specification without waiting on a detection verdict. Glasswall does not claim to detect deceptive hyperlinks, so the mapping is held at low confidence where the entry ran through a credential page rather than carried content.

    Email CDR RelayContent Disarm and ReconstructionGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • manufacturing

    Source: Casio Computer Co., Ltd. · Source: ASCII.jp

  6. Phishing link in emailMedium impactJapan

    Japan Radio Co., Ltd.: One credential entry turned a supplier's account into 994 attack emails to customers

    After the account was taken over, 994 attack emails were sent to Japan Radio's customer addresses on 1 October 2024. The final report of February 2025 confirmed leakage of personal data for the company, its group companies, distributors and business partners, including names, telephone and fax numbers and email addresses, alongside product pricing and contract details. No payment card data was involved.

    The documented vector. Email impersonating a business partner, carrying a URL that led to credential entry. The company's published investigation findings state that on 24 September the employee accessed a URL contained in an email from a business partner and entered their identifier and password, so their sign-in information was stolen. The hijacked account was then used to send targeted attack mail onward.

    How this class of vector is removed

    This event shows the vector class travelling in both directions, and the second direction is the one a file control answers squarely: 994 messages reached customers from a genuine supplier address, where sender trust offered the recipients nothing. Rebuilding inbound content to its format's known good specification and applying relay policy outcomes treats mail from a trusted partner exactly as it treats any other. Glasswall does not claim to detect the deceptive link that started the chain, so the mapping is held at medium confidence and rests on the file layer.

    Email CDR RelayContent Disarm and ReconstructionGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • manufacturing

    Source: Japan Radio Co., Ltd. · Source: ScanNetSecurity

  7. Phishing link in emailHigh impactJapan

    KADOKAWA Corporation: Niconico and group systems taken down by ransomware rooted in phishing

    A ransomware attack detected on 8 June 2024 took down the Niconico video platform and much of the KADOKAWA group's infrastructure for months, with the personal data of 254,241 people affected. The company's August 2024 disclosure presumes entry came from phishing based credential theft from an employee account, and the BlackSuit group claimed the attack.

    The documented vector. Phishing attack against an employee account, the company's stated root cause; mechanism not further specified. KADOKAWA's own disclosure, based on an external forensic investigation, states that employee account information being stolen through phishing and similar attacks is presumed to be the root cause of the incident, while noting that the specific pathway and method remain unknown. This entry carries that qualification rather than firming it up.

    How this class of vector is removed

    The vector class the company named, a phishing message reaching an employee, crosses the boundary as a file: the email itself. On the mail path the relay applies policy outcomes, warn, quarantine or block, to inbound mail, and deterministic rebuild strips active content from whatever a message carries. Glasswall does not claim to detect deceptive hyperlinks, so where the theft ran through a credential page rather than carried content, the mapping is held at low confidence and says so.

    Email CDR RelayContent Disarm and ReconstructionGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • media

    Source: KADOKAWA Corporation · Source: piyolog

  8. File uploadHigh impactSouth Korea

    Modetour Network Inc.: Three million records taken after web shell files were uploaded through the site's own upload function

    Personal data of about 3.06 million members and non-members was exfiltrated from the travel agency following the June 2024 intrusion. In March 2025 the commission imposed penalties totalling about 757 million won, and found that notification had been made two months late.

    The documented vector. Multiple web shell files uploaded through a file upload vulnerability, then executed. The Personal Information Protection Commission's decision records that the attacker exploited a file upload vulnerability to upload multiple web shell files, and executed the malicious code present in those files. The commission found neither file extension validation nor restrictions on execution permissions were in place.

    How this class of vector is removed

    This class of vector arrives through the upload form rather than the inbox, and it is the case a CDR hop on the ingestion path is built for: every uploaded file is routed for rebuild to its format's known good specification, and content with no document format to be rebuilt against, which is what a web shell script is, is blocked or quarantined by policy rather than written to a location that can execute it. Foresight scores structure ahead of that decision. This is a stronger form of the file type validation the commission found absent, because it does not rely on the declared extension.

    ICAP ClientContent Disarm and ReconstructionForesight predictive file triageGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine / Glasswall Foresight

    • travel

    Source: Personal Information Protection Commission

  9. Document downloadHigh impactJapan

    DMM Bitcoin (via wallet provider Ginco Inc.): 4,502 BTC stolen after a malicious script posed as a recruitment test

    After the March 2024 compromise of a Ginco employee, the attackers used stolen session information to impersonate the employee and manipulate a legitimate transaction, stealing 4,502.9 bitcoin worth about 308 million US dollars from DMM Bitcoin in May 2024. The exchange later wound down its business. The December 2024 joint statement by the FBI, DC3 and Japan's National Police Agency attributed the theft to the TraderTraitor group.

    The documented vector. Malicious Python script fetched from a GitHub link, posed as a pre employment test. A North Korean actor posing as a recruiter on LinkedIn sent an employee of Ginco, the wallet software provider for DMM Bitcoin, a URL linking to a malicious Python script under the guise of a pre employment test. The vector is stated verbatim in the joint attribution by the FBI, the US Department of Defense Cyber Crime Center and Japan's National Police Agency.

    How this class of vector is removed

    This class of vector, an executable script fetched over the web under a social pretext, is addressed at the download boundary rather than in the inbox: an ICAP hop routes web downloads through the CDR pipeline, where policy acts on every file and content that cannot be rebuilt to a known good specification, such as raw script files, can be quarantined or blocked rather than delivered. Foresight adds a structural triage score ahead of that decision. The mapping is held at medium confidence because a script is policy handled rather than rebuilt, and the lure arrived outside the corporate mail path.

    ICAP ClientForesight predictive file triageGlasswall Halo / Glasswall Foresight

    • banking

    Source: FBI, DC3 and National Police Agency of Japan · Source: BleepingComputer · Source: Wiz Research

  10. File uploadMedium impactSouth Korea

    HD Korea Shipbuilding & Offshore Engineering and HD Hyundai Construction Equipment: Web shell uploaded through a mobile device management server exposed employee records

    Names and employee identifiers of 9,503 employees and partner staff were exposed following the March 2024 intrusion at the two group companies. The commission issued its decision on 26 August 2026, imposing penalties totalling about 78 million won.

    The documented vector. Web shell file uploaded by exploiting a vulnerability in a mobile device management server. The Personal Information Protection Commission's decision records that the attacker uploaded a web shell file by exploiting a vulnerability in the mobile device management server, and then moved laterally. The commission penalised the file upload safeguard failure alongside the absence of network segmentation.

    How this class of vector is removed

    The same class of vector as the upload cases the commission has penalised elsewhere: a file written through a management interface and then executed. A CDR hop on that ingestion path rebuilds accepted files to their format's known good specification and gives content that cannot be rebuilt, such as a server side script, no route to a location where it can run. The mapping is held at medium confidence because the upload here ran through a management server interface rather than a user facing upload form.

    ICAP ClientContent Disarm and ReconstructionGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • manufacturing

    Source: Personal Information Protection Commission · Source: Seoul Economic Daily

  11. Phishing link in emailContextTaiwan

    D-Link Corporation: Networking manufacturer confirmed a phished employee as the route into its systems

    After data purporting to come from D-Link was offered for sale in October 2023, the company investigated with an external incident response firm and confirmed unauthorised access traced to a phished employee. D-Link says the exposed records came from an outdated product registration system and covered approximately 700 low sensitivity records.

    The documented vector. Phishing email against an employee; D-Link's advisory does not specify the message mechanics further. D-Link's own support announcement states the incident was caused by an employee falling victim to a phishing attack. The advisory does not specify whether the message carried an attachment or a link, and this entry carries that limit rather than filling it in.

    How this class of vector is removed

    The vector class the company named, a phishing message reaching an employee, crosses the boundary as a file: the email itself. A CDR hop on inbound mail applies policy outcomes, warn, quarantine or block, and rebuilds carried content to a known good specification before delivery. Glasswall does not claim to detect deceptive hyperlinks, so where the compromise ran through a credential page rather than carried content the mapping is held at low confidence and says so.

    Email CDR RelayContent Disarm and ReconstructionGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • manufacturing

    Source: D-Link Corporation · Source: BleepingComputer

  12. Document downloadHigh impactAustralia

    FIIG Securities Limited: A zip archive holding a disguised script opened the breach behind Australia's first cyber penalty

    From 19 May 2023 the attacker used the downloaded script to fetch a second stage and establish persistence, reached a privileged account by 23 May, and exfiltrated about 385 gigabytes including driver's licences, passports, tax file numbers and bank details, with around 18,000 clients notified. The ALPHV group published data in June 2023. In February 2026 the Federal Court imposed a 2.5 million dollar penalty, the first Australian civil penalty for cybersecurity failures under financial services licence obligations.

    The documented vector. Zip archive containing a JavaScript file named to look like a security agreement. The corporate regulator's statement of claim records that an employee downloaded a zip file while browsing the internet, and that the archive contained a JavaScript file named "second ranking general security agreement 85822.js", which invoked the Windows script host. The archive and the disguised script are documented in the pleadings rather than in the judgment.

    How this class of vector is removed

    This class of vector, an executable script hidden inside an archive and named to look like a routine business document, is addressed at the download boundary: an ICAP hop routes web downloads through the CDR pipeline, where the archive is opened and its contents assessed, and a raw script, which has no document format to be rebuilt against, is quarantined or blocked by policy rather than delivered under its filename. Foresight scores the structure ahead of that decision. The mapping is held at medium confidence because a script is policy handled rather than rebuilt.

    ICAP ClientContent Disarm and ReconstructionForesight predictive file triageGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine / Glasswall Foresight

    • banking

    Source: Australian Securities and Investments Commission · Source: Federal Court of Australia · Source: Australian Securities and Investments Commission

  13. Malicious emailMedium impactJapan

    University of Tokyo, Graduate School of Arts and Sciences: Targeted attack email infected a professor's machine, exposing 4,000 records

    A professor's PC at the Graduate School of Arts and Sciences on the Komaba campus was infected via a targeted attack email in July 2022, with roughly 4,000 records on students, staff, alumni and academic society members potentially exfiltrated. The university disclosed the incident in October 2023 after investigation.

    The documented vector. Targeted attack email carrying malware; the university's disclosure names the email as the infection route. The university's disclosure states that a faculty member's work from home PC was infected with malware by a targeted attack email received on 19 July 2022, with the lure styled as a lecture or interview request. The disclosure names the email as the route without separating attachment from link, and this entry carries that wording.

    How this class of vector is removed

    This class of vector, a targeted email delivering malware to one chosen recipient, is exactly where detection struggles and deterministic controls hold: content carried by inbound mail is rebuilt to its format's known good specification with active content stripped, whatever the lure, and policy outcomes apply to the message itself. Foresight scores anomalous file construction before anything runs. The mapping is held at medium confidence because the disclosure does not separate attachment from link.

    Content Disarm and ReconstructionEmail CDR RelayForesight predictive file triageGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine / Glasswall Foresight

    • education

    Source: The University of Tokyo · Source: ITmedia

  14. Malicious emailMedium impactJapan

    University of Tokyo, Institute for Future Initiatives: A second targeted attack email at the same university leaked 207 people's data

    A targeted attack email infected a PC at the University of Tokyo's Institute for Future Initiatives in July 2022, leaking data on 207 people. Together with the Komaba incident the same month, the record shows a sustained email borne campaign against the university.

    The documented vector. Targeted attack email carrying malware; the institute's notice names the email as the infection route. The institute's official notice states a staff PC was infected with malware by a targeted attack email received in mid July 2022. Leakage was confirmed in January 2023, covering personal data including bank account details held in administrative documents.

    How this class of vector is removed

    The same class of vector as the Komaba incident, a targeted email carrying malware to a specific recipient, is removed at the mail boundary: carried content is rebuilt to the format's known good specification before delivery, policy outcomes apply to the message, and Foresight scores structural anomalies ahead of the pipeline. Held at medium confidence because the notice does not separate attachment from link.

    Content Disarm and ReconstructionEmail CDR RelayForesight predictive file triageGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine / Glasswall Foresight

    • education

    Source: University of Tokyo, Institute for Future Initiatives · Source: Mynavi News

  15. Email attachmentMedium impactJapan

    RIKEN: Japan's largest research institute infected in the Emotet wave, then impersonated in spoofed mail

    RIKEN, Japan's largest comprehensive research institution, confirmed in March 2022 that it had been infected with Emotet, after which emails impersonating its staff, using real names and departments, were sent to outside contacts. The institute issued a public warning about the spoofed mail and its attachments.

    The documented vector. Emotet emails carrying zip archives and macro bearing files. RIKEN confirmed an Emotet infection during the March 2022 wave and warned that the spoofed messages sent in its name carried zip files and macro bearing files. Japan's Information technology Promotion Agency documented the same wave as driven by malicious Excel macro attachments.

    How this class of vector is removed

    This class of vector, macro bearing Office files and archives arriving by email, is removed by deterministic CDR rebuild: the document is reconstructed to its format's known good specification and the macro is not carried into the rebuilt file, while macro intelligence inspects embedded active content for the policy decision. The Email CDR Relay puts that rebuild on inbound mail, so the control does not wait for a signature covering that week's Emotet build.

    Content Disarm and ReconstructionMacro intelligenceEmail CDR RelayGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • research

    Source: ScanNetSecurity · Source: Information technology Promotion Agency (IPA)

  16. Phishing link in emailHigh impactAustralia

    Australian Clinical Labs Limited (Medlab Pathology): Phishing email recorded as the vector behind Australia's first Privacy Act penalty

    The Quantum ransomware group compromised the Medlab Pathology network on or before 25 February 2022, exfiltrated 86 gigabytes and published it to the dark web by June 2022, exposing passport numbers, health information and payment card details for at least 223,269 individuals. In October 2025 the Federal Court imposed 5.8 million dollars in civil penalties, the first ever under the Privacy Act. The commissioner's filing also records that the company relied on its mail platform's built in malware detection and retained firewall logs for one hour.

    The documented vector. Phishing email addressed to an employee, per the Information Commissioner's court filing. The Australian Information Commissioner's concise statement records that the company's forensic provider concluded the attack vector was a phishing email addressed to an employee. The commissioner records that conclusion while criticising the adequacy of the engagement that produced it, and this entry carries the finding with that qualification attached rather than as a finding of the court.

    How this class of vector is removed

    The vector class recorded in the filing, a phishing email reaching an employee, crosses the trust boundary as a file: the message and anything it carries. A CDR hop on inbound mail rebuilds carried content to its format's known good specification and applies policy outcomes to the message, which is a different control from the platform malware detection the filing describes, because it does not depend on recognising the threat. Glasswall does not claim to detect deceptive hyperlinks, so the mapping is held at low confidence where the record does not state what the message carried.

    Email CDR RelayContent Disarm and ReconstructionGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • healthcare

    Source: Office of the Australian Information Commissioner · Source: Office of the Australian Information Commissioner

  17. Email attachmentMedium impactJapan

    Kracie Holdings, Ltd.: Emotet reached a consumer goods maker through an encrypted attachment

    Kracie Holdings disclosed in February 2022 that an Emotet infection had leaked email addresses and led to impersonation emails being sent to its contacts. The infection route was confirmed in the same Nikkei xTECH survey of the disclosing companies.

    The documented vector. Encrypted (password protected) file attached to email, carrying Emotet. Nikkei xTECH's survey records Kracie's infection route as an encrypted file attached to an email, the same technique used across the February 2022 wave to carry the payload past inline inspection.

    How this class of vector is removed

    This class of vector, malware packed inside a password protected attachment, is removed by treating the encrypted file as unreadable rather than as trusted: it is held, released to the legitimate recipient, and rebuilt to the format's known good specification once decrypted, so the delivered document is reconstructed rather than merely scanned and passed.

    Content Disarm and ReconstructionEmail CDR RelayQuarantineGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • manufacturing

    Source: Nikkei xTECH · Source: ScanNetSecurity

  18. Email attachmentMedium impactJapan

    Wacoal Corp.: Encrypted email attachment carried Emotet into the apparel maker's network

    Wacoal disclosed in February 2022 that an employee PC had been infected with Emotet, leading to theft of email information and spoofed messages sent to its contacts. It was one of the companies whose infection route Nikkei xTECH confirmed directly with the organisation.

    The documented vector. Encrypted (password protected) file attached to email, carrying Emotet. Nikkei xTECH's survey of the disclosing companies records Wacoal's infection route as an encrypted file attached to an email. The password protection is the point of the technique: it defeats inline inspection of the attachment in transit.

    How this class of vector is removed

    The same class of vector as the other disclosures in this wave, an encrypted attachment whose contents no gateway scanner can read in transit, is handled by holding the file and rebuilding it at release: the recipient supplies the password, CDR reconstructs the document to its format's known good specification, and what lands on the desktop no longer carries the loader.

    Content Disarm and ReconstructionEmail CDR RelayQuarantineGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • manufacturing

    Source: Nikkei xTECH · Source: ScanNetSecurity

  19. Email attachmentMedium impactJapan

    Lion Corporation: Emotet arrived as an encrypted email attachment, leaking mail data and spawning impersonation emails

    Lion Corporation disclosed on 3 February 2022 that an employee PC had been infected with Emotet, leaking email addresses and mail data from its mail environment and triggering waves of impersonation emails to customers and partners. The company published a notice the following day.

    The documented vector. Encrypted (password protected) file attached to email, carrying Emotet. Nikkei xTECH surveyed the companies that disclosed Emotet infections in the January and February 2022 wave and established each one's infection route. Lion's route was an encrypted file attached to an email, the password protected pattern that puts a payload beyond inline scanning, which JPCERT/CC documented across the same wave.

    How this class of vector is removed

    This class of vector, a password protected attachment carrying commodity malware, is the case inline scanning cannot resolve: the file arrives as opaque ciphertext. Quarantine holds it and releases a rebuilt copy once the legitimate recipient supplies the password, so the document reaches the user reconstructed to its format's known good specification rather than as the attacker packed it, with the Email CDR Relay applying that rebuild across inbound mail.

    Content Disarm and ReconstructionEmail CDR RelayQuarantineGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • manufacturing

    Source: Lion Corporation · Source: Nikkei xTECH · Source: JPCERT/CC

  20. Phishing link in emailMedium impactJapan

    Sekisui House, Ltd.: Emotet reached the housing group through a URL in the body of an email

    Sekisui House disclosed an Emotet infection in January 2022 that harvested email data and led to impersonation emails being sent to its contacts. Nikkei xTECH established the infection route for each disclosing company in the wave, and the group later moved away from password protected attachment practices.

    The documented vector. URL in the email body, leading to the Emotet payload. Nikkei xTECH's survey of the disclosing companies records Sekisui House's infection route as a URL in the body of an email, rather than an attachment. The same wave used both routes, which is why this record distinguishes them.

    How this class of vector is removed

    This class of vector puts the payload one step behind the message, so the control sits at the fetch rather than the inbox: an ICAP hop routes the resulting web download through CDR, rebuilding the delivered file to its format's known good specification before it reaches the desktop, while the mail relay applies policy outcomes to the message itself. Glasswall does not claim to detect deceptive hyperlinks, so this mapping addresses what the link delivers, not the link.

    ICAP ClientContent Disarm and ReconstructionEmail CDR RelayGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • construction

    Source: Nikkei xTECH · Source: ScanNetSecurity

  21. Email attachmentMedium impactPhilippines

    PowerVision EAP, Inc.: Compromised mailbox mailed a credential harvesting file to 387 recipients

    PowerVision's administrative mailbox was compromised on 20 May 2021 and used to send credential harvesting emails to 387 recipients from the company's own address. The company deactivated the account and imposed multi-factor authentication across all email accounts four days later. The commission found insufficient grounds for a notification exemption and ordered notification plus the missing breach report details.

    The documented vector. Audio file that prompted the recipient to enter their Outlook email address and password. The commission's order records that the company's administrative mailbox was reached by password cracking, not by a file, and was then used to send emails containing an audio file that would require the person accessing it to input the Outlook email and password. The file-borne element of this event is that outbound wave, and this entry does not claim otherwise about the initial compromise.

    How this class of vector is removed

    This class of vector is instructive from the receiving side: the 387 recipients were sent a file from a genuine, trusted sender address, so sender reputation offered them nothing. Rebuilding every inbound attachment to its format's known good specification strips the active content a harvesting file depends on, regardless of who the message appears to come from, and the relay applies policy outcomes to the message itself.

    Content Disarm and ReconstructionEmail CDR RelayGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • services

    Source: National Privacy Commission

  22. Email attachmentHigh impactNew Zealand

    Waikato District Health Board: Hospital network taken down by ransomware the board attributed to an email attachment

    On 18 May 2021 ransomware disabled IT systems and phones across Waikato, Thames, Tokoroa, Te Kuiti and Taumarunui hospitals. Surgeries were postponed, radiation therapy was suspended with some cancer patients transferred, and services ran on paper for roughly four weeks. After the government declined to pay, attackers leaked patient, staff and financial data on the dark web on 29 June 2021. Full clinical restoration took until mid June 2021.

    The documented vector. Malicious email attachment (file type not published), the board's stated initial incursion. Waikato District Health Board stated publicly that it believed the initial incursion was via an email attachment, and contemporaneous national reporting described the malware as arriving in an email attachment as part of a phishing campaign. The vector stands as the board's own day one assessment: the published incident analysis has its malicious activity sections withheld in full, so the attribution was never independently confirmed on the public record, nor was it retracted.

    How this class of vector is removed

    The vector as the board stated it, a malicious email attachment, belongs to a class that is removed by deterministic CDR rebuild: inbound attachments are rebuilt to their format's known-good specification and stripped of active content before delivery, independent of any detection verdict on the specific ransomware family. The Email CDR Relay applies that rebuild on the mail path. The mapping is held at medium confidence because the vector rests on the organisation's stated assessment rather than a published forensic report.

    Content Disarm and ReconstructionEmail CDR RelayGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • healthcare

    Source: eHealthNews.nz (HiNZ) · Source: RNZ

  23. Email attachmentHigh impactPhilippines

    Costa Crociere S.p.A. (AIDA Cruises): Malicious Excel attachments opened the intrusion that exposed 74,000 Filipino data subjects

    After the Excel attachments were opened on 21 December 2020, the attacker exfiltrated roughly 1.1 terabytes of data and deployed DoppelPaymer ransomware, detected on 25 December. About 74,000 Filipino data subjects, guests, employees and crew, had names, dates of birth, passport numbers, nationality and trip data exposed. The commission denied the operator's request for exemption from individual notification, ordered notification and the overdue full breach report, and required it to show cause against contempt proceedings.

    The documented vector. Malicious Excel documents carrying SDBot remote access tooling. The National Privacy Commission's resolution records that the event began via multiple malicious Excel documents, sent by email, containing SDBot remote access tooling, which were opened by employees at AIDA. The attacker then pivoted from the AIDA network into the Costa network before deploying ransomware.

    How this class of vector is removed

    This class of vector, a spreadsheet carrying remote access tooling into an organisation by email, is removed by deterministic CDR rebuild: the workbook is reconstructed to its format's known good specification, so embedded active content does not survive into the file the employee opens, and macro intelligence inspects that active content for the policy decision. The Email CDR Relay places the rebuild on inbound mail, ahead of any verdict on whether the particular tooling is known.

    Content Disarm and ReconstructionMacro intelligenceEmail CDR RelayGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • travel

    Source: National Privacy Commission

  24. Email attachmentMedium impactSingapore

    ST Logistics Pte Ltd: Defence personnel data put at risk after staff opened a malicious .doc attachment carrying Emotet

    ST Logistics, a logistics vendor to Singapore's Ministry of Defence and armed forces, suffered an Emotet infection that placed unencrypted files holding personal data of about 2,400 MINDEF and SAF personnel at risk, with up to 4,000 individuals potentially affected. MINDEF disclosed the incident on 21 December 2019, and the Personal Data Protection Commission's grounds of decision, which documents the vector, imposed a financial penalty in 2021. No evidence of actual data leakage was found.

    The documented vector. Malicious .doc email attachments delivering the Emotet trojan. On 2 October 2019, ST Logistics staff received phishing emails spoofing internal senders, each carrying an attachment with the file extension .doc. The PDPC's published decision records that 13 users opened the malicious attachment, after which Emotet installed on laptops, harvested mailboxes and sent around 100 further phishing emails.

    How this class of vector is removed

    This class of vector, a macro-bearing document attachment delivering a commodity trojan, is removed by deterministic CDR rebuild: the .doc is rebuilt to the format's known-good specification and its macros and other active content are stripped before the file reaches a user, with no dependence on any recipient spotting the spoof. The Email CDR Relay applies that rebuild to inbound mail before delivery.

    Content Disarm and ReconstructionEmail CDR RelayGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • logistics

    Source: Personal Data Protection Commission · Source: Personal Data Protection Commission · Source: Ministry of Defence Singapore

  25. Phishing link in emailMedium impactAustralia

    RI Advice Group Pty Ltd: Court's agreed facts document email delivered ransomware and a credential capturing file behind a cloud link

    Nine cyber incidents across the licensee's authorised representative practices were put before the Federal Court, which in May 2022 made the first Australian finding that a financial services licensee had breached its licence obligations through cybersecurity failures. The agreed contributing failures included no filtering or quarantining of emails and absent or outdated antivirus. The licensee paid 750,000 dollars in costs and was ordered to engage a cybersecurity expert.

    The documented vector. Phishing emails linking to a cloud storage folder holding a credential capturing file; a separate incident in the same findings was ransomware delivered by email. The statement of agreed facts annexed to the Federal Court's 2022 judgment records that phishing emails were sent to over 150 clients asking recipients to click a link to a cloud storage folder, and that the folder contained a file that was capturing credentials. The same agreed facts record an earlier incident where a practice's reception computer was hit by ransomware delivered by email.

    How this class of vector is removed

    Both documented classes of vector here sit on the mail path. Ransomware delivered by email is removed by rebuilding inbound attachments to their format's known good specification before delivery, and where the message instead points at a file in cloud storage, an ICAP hop routes that download through the same rebuild. The court's agreed facts note that no filtering or quarantining of email was in place, which is the control layer this maps to, and the relay applies allow, warn, quarantine and block outcomes there.

    Email CDR RelayContent Disarm and ReconstructionICAP ClientGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • banking

    Source: Federal Court of Australia

  26. Email attachmentHigh impactAustralia

    The Australian National University: Campaign against university systems used malicious Word attachments to harvest credentials

    A sophisticated actor operated inside ANU's network for about six weeks from November 2018, targeting the domain holding human resources, financial and student administration records. ANU initially feared up to 19 years of personal records had been taken; later forensics indicated substantially less, though the exact records could not be determined. The university disclosed the breach in June 2019 and published a detailed public incident report in late 2019, which remains the authoritative account.

    The documented vector. Malicious Word documents that sent users' credentials to attacker infrastructure when opened. ANU's incident report documents that the initial infection was an interaction-less spear-phishing email, and that the attackers' second, third and fourth spear-phishing cycles then delivered malicious Word document attachments. In the report's words, the user opened the attached Word document and the credentials were sent to the remote server, with all attachments in those cycles using the same technique.

    How this class of vector is removed

    The documented file-borne stages of this campaign, malicious Word attachments carrying credential-harvesting code, belong to a class of vector that is removed by deterministic CDR rebuild: each attachment is rebuilt to the format's known-good specification with macros and active content stripped, so the document that reaches the user cannot call out to attacker infrastructure. The Email CDR Relay applies the rebuild on inbound mail. The campaign's initial interaction-less email sits outside this class, which is why this entry maps the attachment cycles and not the whole intrusion.

    Content Disarm and ReconstructionEmail CDR RelayGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • education

    Source: The Australian National University · Source: ABC News

  27. Malicious emailHigh impactSingapore

    Singapore Health Services (SingHealth): 1.5 million patients' data taken in a breach the COI traced to a phishing email carrying malicious code

    Attackers compromised a front end workstation around 23 August 2017, moved laterally for months, and between 27 June and 4 July 2018 exfiltrated the personal particulars of about 1.5 million patients plus the outpatient dispensed medicine records of about 160,000, including the Prime Minister, who the Ministry of Health said was specifically and repeatedly targeted. The breach was disclosed on 20 July 2018, and the Committee of Inquiry's public report of January 2019 remains the authoritative account.

    The documented vector. Phishing email carrying malicious code, the message itself the carrier; a hacking tool was later installed via an unpatched Outlook vulnerability. The Committee of Inquiry's public report assessed that initial entry to SingHealth's network was "likely by way of a phishing email containing malicious code" which infected a front end workstation, while recording that CSA could not conclusively determine the source of the initial infection. The report also documents that a publicly available hacking tool was installed on that workstation by exploiting an unpatched Microsoft Outlook vulnerability, and that a later phishing email in the campaign would run automatically when previewed or read.

    How this class of vector is removed

    The vector class the Committee described, a phishing email carrying malicious code, crosses the trust boundary as a file: the message and whatever it carries. A CDR hop on the mail path rebuilds inbound attachments to their format's known good specification and applies policy outcomes, warn, quarantine or block, to inbound mail, so the malicious code class the report describes is removed from rebuilt content rather than waited on by detection. The mapping is held at medium confidence because the Committee itself qualified the finding on the initial infection's source.

    Content Disarm and ReconstructionEmail CDR RelayGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • healthcare

    Source: Committee of Inquiry, Government of Singapore · Source: Ministry of Health Singapore

  28. Email attachmentHigh impactIndia

    Union Bank of India: 171 million dollar SWIFT heist attempt began with an RBI-lookalike email attachment

    In July 2016 attackers used malware delivered via an RBI-lookalike email attachment to steal Union Bank of India's SWIFT access and issue transfer instructions of about 171 million US dollars through the bank's overseas nostro account, closely mirroring the Bangladesh Bank heist. The bank traced the funds across several jurisdictions and blocked or recovered the money within days; chairman Arun Tiwari publicly confirmed the incident and the recovery, and the Central Bureau of Investigation later took over the case.

    The documented vector. Malicious email attachment styled as Reserve Bank of India correspondence, dropping malware. A bank employee opened an email attachment which looked as if it had been sent by the Reserve Bank of India, as documented in The Wall Street Journal's investigation of the incident. The attachment dropped malware through which the attackers obtained the bank's SWIFT access codes.

    How this class of vector is removed

    This class of vector, a document attachment impersonating a trusted institution to drop malware, is removed by deterministic CDR rebuild: the attachment is rebuilt to its format's known-good specification and stripped of active content before delivery, so the dropper does not reach the employee regardless of how credible the sender appears. The Email CDR Relay puts that rebuild on the mail path, and Foresight can score the file's structure ahead of the pipeline to flag likely-malicious construction for the security team.

    Content Disarm and ReconstructionEmail CDR RelayForesight predictive file triageGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine / Glasswall Foresight

    • banking

    Source: MediaNama · Source: Business Standard

  29. Email attachmentHigh impactTaiwan

    First Commercial Bank: ATM heist cashed out through the bank's own update server after spear-phishing entry

    In July 2016 the Cobalt group withdrew about NT$83 million from 41 First Commercial Bank ATMs in Taipei, using malware distributed through the bank's own ATM software update server after a months earlier network intrusion first observed in firewall logs on 31 May 2016. The MJIB investigated, three money mules were convicted in Taiwanese courts and most of the cash was recovered.

    The documented vector. Spear-phishing email; investigators describe attachments exploiting a Microsoft Office vulnerability. Investigators from the Ministry of Justice Investigation Bureau, in accounts carried by AmCham Taiwan's reporting, traced initial access to a spear-phishing attack against a call centre worker serving the bank's London branch, with emails delivering attachments built to exploit a Microsoft Office vulnerability. The MJIB's published brief documents the chain from the compromised London call recording server onward, so the attachment detail rests on the investigators' account rather than the brief itself.

    How this class of vector is removed

    The class of vector investigators described, a document attachment built to exploit its own parser, is removed by deterministic CDR rebuild: every inbound attachment is reconstructed to the format's known good specification, so a file whose value to the attacker is its malformed construction does not survive delivery, with no dependence on a signature for the exploit. The Email CDR Relay applies that rebuild on the mail path, and Foresight scores exactly this kind of anomalous construction before anything runs. The mapping is held at medium confidence because the attachment detail rests on investigators' accounts rather than the published brief.

    Content Disarm and ReconstructionEmail CDR RelayForesight predictive file triageGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine / Glasswall Foresight

    • banking

    Source: Ministry of Justice Investigation Bureau · Source: Taiwan Business TOPICS (AmCham Taiwan) · Source: Group-IB

  30. Email attachmentHigh impactJapan

    JTB Corp.: 7.93 million customer records exposed after a booking-document lure installed PlugX

    JTB disclosed on 14 June 2016 that personal data of about 7.93 million customers had been exposed, including names, addresses, email addresses and more than 4,300 valid passport numbers. The intrusion began in March 2016 when an employee opened a malicious email attachment, installing PlugX; Japanese police investigated the incident.

    The documented vector. Malicious document attachment posing as an airline booking document, delivering the PlugX remote access trojan. An employee of JTB subsidiary i.JTB opened a targeted email attachment disguised as an airline booking document. Opening the file installed the PlugX remote access trojan, from which the attackers reached the server holding customer booking data. The attachment vector is consistently documented across threat intelligence and contemporaneous press reporting of JTB's disclosure.

    How this class of vector is removed

    This class of vector, a weaponised document lure carrying a remote access trojan, is removed by deterministic CDR rebuild: the attachment is rebuilt against the format specification and active content is stripped, so the document that reaches the employee no longer carries the loader, whatever the lure looks like. The Email CDR Relay places that rebuild on inbound mail before delivery.

    Content Disarm and ReconstructionEmail CDR RelayGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • travel

    Source: NSFOCUS · Source: TravelMole · Source: SiliconANGLE

  31. Email attachmentHigh impactSouth Korea

    Interpark: Over 10 million customers' data stolen after one tailored malware attachment was opened

    Attackers intruded into the online retailer Interpark in May 2016; the breach was discovered on 11 July 2016 after a 3 billion won bitcoin extortion demand. Personal data of more than 10 million customers, around 26.6 million data items including identifiers, phone numbers and addresses, was stolen. The ICT Ministry and the Korea Communications Commission published investigation findings, and the National Police Agency attributed the operation to North Korea's Reconnaissance General Bureau.

    The documented vector. Malware attachment on a spear-phishing email crafted to match a targeted employee's routine correspondence. Attackers studied a specific Interpark employee's email patterns and delivered malware in an attachment styled as routine correspondence. The published investigation account states that once the employee opened the malware attachment, the infection spread through Interpark's networked computers.

    How this class of vector is removed

    This class of vector, a malware attachment tailored to look like routine correspondence, is removed by deterministic CDR rebuild precisely because the control does not judge the lure: every inbound attachment is rebuilt to the format's known-good specification and stripped of active content, however convincing the email around it is. The Email CDR Relay places that rebuild on the mail path before delivery.

    Content Disarm and ReconstructionEmail CDR RelayGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine

    • retail

    Source: The Korea Herald · Source: Security Affairs

  32. Email attachmentHigh impactJapan

    Japan Pension Service: 1.25 million pension records exfiltrated after staff opened malicious email attachments

    Staff at the Japan Pension Service opened malware-laden email attachments in May 2015, giving attackers a foothold on the internal network. Roughly 1.25 million records, including basic pension numbers and names covering about 1.01 million people, were exfiltrated between 21 and 23 May 2015. The service disclosed the breach on 1 June 2015, and official verification reports followed from the ministry's committee, NISC and the Board of Audit of Japan.

    The documented vector. Malicious file attachments carrying the Emdivi remote access trojan. Targeted emails carrying attachments that contained malicious programs were sent to Japan Pension Service staff, and the infection began when staff opened those attachments. The Board of Audit of Japan's report documents the attachment delivery, and JPCERT/CC identified the malware as the Emdivi family used in the Blue Termite campaign of targeted attacks on Japanese organisations.

    How this class of vector is removed

    This class of vector, a malicious document arriving as an email attachment, is removed by deterministic CDR rebuild: every inbound attachment is rebuilt to its format's known-good specification, stripping macros, embedded objects and other active content without depending on a detection verdict, which matters when the payload is a targeted trojan no signature yet describes. On the mail path, the Email CDR Relay applies that rebuild before delivery, and Foresight can score the attachment's structure ahead of the pipeline to flag anomalous construction before anything runs.

    Content Disarm and ReconstructionEmail CDR RelayForesight predictive file triageGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine / Glasswall Foresight

    • government

    Source: Board of Audit of Japan · Source: JPCERT/CC · Source: The Japan Times

  33. Email attachmentHigh impactSouth Korea

    Korea Hydro & Nuclear Power Co.: Nuclear operator hit by thousands of spear-phishing emails carrying weaponised HWP documents

    Attackers targeted Korea Hydro and Nuclear Power with a mass spear-phishing wave in December 2014, then leaked reactor blueprints, manuals and personal data of about 10,000 employees online alongside threats against the plants. The prosecutors' joint investigation concluded in March 2015 that the malicious code matched the Kimsuky malware family attributed to North Korea.

    The documented vector. Hangul Word Processor (HWP) documents exploiting a parser vulnerability to drop a disk-wiping payload. Between 9 and 12 December 2014, attackers sent 5,986 phishing emails containing malicious code to 3,571 KHNP employees, figures published by the Seoul Central District Prosecutors' Office joint investigation. Contemporaneous technical analysis documents the carrier as HWP documents exploiting a Hangul Word Processor vulnerability and delivering a master boot record wiper.

    How this class of vector is removed

    This class of vector, a document weaponised against its own parser, is removed by deterministic CDR rebuild: the file is reconstructed to the format's known-good specification, so a document built to trigger a parser flaw does not survive the rebuild intact, and no prior signature for the exploit is needed. The Email CDR Relay applies the rebuild to inbound attachments before delivery, and Foresight scores structural anomalies of exactly this kind, malformed construction that exists to exploit, before anything runs.

    Content Disarm and ReconstructionEmail CDR RelayForesight predictive file triageGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine / Glasswall Foresight

    • energy

    Source: Reuters · Source: Trend Micro · Source: 38 North

Scope

How to read this timeline

Every event on this page meets three tests before it is published. It is documented by reliable public sources: a regulator, an official inquiry, the affected organisation's own disclosure, or reputable press with named confirmation, and each entry links to those sources. The initial access or payload delivery travelled as a file, as the public record states it. An email is itself a file, so malicious code in a message and deceptive-hyperlink phishing carried by a message both count; credential attacks and pure network exploits are excluded. And the prevention analysis is conditional: where we say a capability removes a class of vector, that is a statement about how the control treats that class of content, not a claim about what any organisation ran, and not a judgement on the people who dealt with the incident.

This page is a working reference, not an incident report or legal advice. Details reflect the public record on the review date and organisations named here are cited from that record alone.

The same vectors reach your boundary