Casio Hit by Underground Ransomware Causing Major Data Breach

Incident Date:

October 10, 2024

World map

Overview

Title

Casio Hit by Underground Ransomware Causing Major Data Breach

Victim

Casio Computer Co., Ltd

Attacker

Underground Team

Location

Shibuya City, Japan

, Japan

First Reported

October 10, 2024

Casio Computer Co., Ltd. Falls Victim to Underground Ransomware Attack

Casio Computer Co., Ltd., a leading Japanese electronics manufacturer, has been targeted by the Underground ransomware group, resulting in a significant data breach. The attack, which occurred on October 5, led to the exfiltration of approximately 204.9 GB of sensitive data, including confidential documents and personal information.

Casio: A Leader in Electronics

Founded in 1957 and headquartered in Shibuya, Tokyo, Casio is renowned for its innovative electronic products, including timepieces, calculators, and electronic musical instruments. The company reported net sales of ¥268.83 billion as of March 31, 2024, and employs around 9,594 individuals globally. Casio's commitment to innovation and quality has established it as a prominent player in the electronics industry.

Details of the Ransomware Attack

The Underground ransomware group infiltrated Casio's network, causing system failures and service disruptions. The attackers accessed and leaked sensitive data, including employee personal information, confidential NDAs, and financial documents. Casio confirmed the breach and is working with external specialists to assess the damage. The company assured that no credit card information was compromised, as it is stored separately.

About the Underground Ransomware Group

The Underground ransomware group, associated with the RomCom cybercrime organization, has been active since July 2023. Known for targeting Windows systems, the group employs sophisticated tactics, including exploiting vulnerabilities like CVE-2023-36884 and using phishing emails. The group distinguishes itself by not altering file extensions during encryption, focusing on high-value targets.

Potential Vulnerabilities and Penetration Tactics

Casio's global operations and extensive data handling make it a lucrative target for cybercriminals. The Underground group likely exploited vulnerabilities in Casio's network infrastructure, possibly through phishing or remote code execution flaws. The breach highlights the importance of effective cybersecurity measures to protect sensitive data.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.