JR East: Over 2 Million Members' Data Possibly Leaked at Eki-net and Other Services

ロイター··JP·Read original
3▲0 ▼3Impact / 5
Summary · why it matters

East Japan Railway Company announced on the 9th that more than 2 million members' information from its ticket reservation and travel support services "Eki-net" and "Otona no Kyujitsu Club" may have been leaked due to unauthorized access to a cloud service operated by a SoftBank subsidiary. Approximately 1.67 million email addresses of Eki-net members may have been compromised, while about 390,000 records from Otona no Kyujitsu Club, including membership numbers and credit card expiration dates, may have been leaked. Names, addresses, phone numbers, and credit card numbers were not included. In addition, email distribution to members of both services has been partially disrupted. IDC Frontier, the SoftBank subsidiary, suffered a ransomware attack on part of the systems of its cloud service "IDCF Cloud," affecting a wide range of contracted companies and local governments.

Impact on assets 3

Smart City / Autonomous Infrastructure▼
East Japan Railway Company
9020
▼ NegativeRegulationrelevance

Over 2 million members' data from JR East's Eki-net and Otona no Kyujitsu Club services may have leaked via unauthorized access to a SoftBank subsidiary's cloud, and member email distribution was disrupted.

Digital Finance & Tokenization▼
SoftBank Corp.
9434
▼ NegativeRegulationrelevance

SoftBank Corp.'s subsidiary IDC Frontier was hit by a ransomware attack on its IDCF Cloud, affecting a wide range of contracted companies and local governments.

Artificial Intelligence▼
SoftBank Group Corp.
9984
▼ NegativeRegulationrelevance

SoftBank subsidiary IDC Frontier suffered a ransomware attack on its IDCF Cloud, exposing data of contracted companies and local governments including JR East.

Theme Impact 3

Related news

JapanUnited States
▲

Unauthorized Access Surges, Cyber Defense Inquiries Flood In as Hitachi, Fujitsu, and NEC Strengthen Systems

As unauthorized access to companies surges, electronics giants offering cyber defense services are receiving a flood of consultations and inquiries. In September, Hitachi launched a service that uses advanced AI models from U.S. firms such as Anthropic and OpenAI to provide end-to-end support spanning risk assessment, monitoring, and recovery. Fujitsu announced its cyber defense strategy in late August, and inquiries from client companies have poured in since then, increasing further in recent days, prompting it to establish a specialized organization of about 100 people effective October 1. NEC began offering a service in late September for financial institutions, manufacturers, and distributors that uses AI to automatically analyze risks and formulate response policies. Each company is strengthening its systems in anticipation of sophisticated AI-driven cyberattacks, and demand appears set to keep expanding.
About megatrends
Cybersecurity & Digital Trust › Cyber Resilience & Ransomware Recovery ▲Demand
Cybersecurity & Digital Trust › Network Security & SASE ▲Demand
6501.JP · Demand · Positive Hitachi launched an AI-based cyber defense service and is receiving a flood of consultations as unauthorized access surges.
6701.JP · Demand · Positive NEC began offering an AI cyber-risk service in late September to financial, manufacturing, and distribution clients amid surging attacks.
6702.JP · Demand · Positive Fujitsu's cyber defense inquiries have poured in since its late-August strategy announcement, prompting a new ~100-person specialized organization.
Read original ↗
時事通信·10hRead more →
Japan
2

Japan's FSA Asks Financial Institutions to Review Cyber Defenses, Tighten Driver's License Image Checks

Japan's Financial Services Agency on the 9th, following a spate of customer data leaks caused by unauthorized access, called on financial institutions to review their cybersecurity measures and issued a warning. It is asking them to thoroughly check images of driver's licenses and other ID documents for anything unusual, even when verifying identity without meeting customers face to face. The FSA stressed that it wants institutions to prevent the fraudulent use of financial services and act so as not to undermine trust, urging them to review their response plans for cyberattacks and to promptly take any necessary measures where shortcomings are found. Financial Services Minister Satsuki Katayama said at a post-cabinet press conference on the 9th that identity verification should be carried out appropriately, including by reading IC chip information, which is extremely effective as a countermeasure against fraud. The Ministry of Economy, Trade and Industry announced it will issue warnings to roughly 1,000 industry associations under its jurisdiction, including those in the automotive and retail sectors, calling on management to take the lead in checking communications equipment and systems for vulnerabilities.
About megatrends
Cybersecurity & Digital Trust › Identity & Access Management ▼Regulation
Cybersecurity & Digital Trust › Data Security & Cyber Resilience Regulation
Read original ↗
時事通信·2dRead more →
Japan

METI Issues Alert to About 1,000 Industry Groups After Spate of Unauthorized Access Incidents

Economy, Trade and Industry Minister Ryosei Akazawa said at a post-cabinet meeting press conference on the 9th that, in response to a series of incidents involving information leaks and other damage from unauthorized access in Japan, the ministry issued a broad alert the same day through roughly 1,000 industry groups under its jurisdiction. Akazawa called on companies to act on the understanding that they must manage security not only within their own operations but across the entire supply chain, and urged top management to take responsibility in securing the necessary resources and directing the response. He also encouraged them to quickly identify and address vulnerability information, monitor all activity on internal systems, and promptly provide information when damage occurs.
About megatrends
Cybersecurity & Digital Trust › Data Security Posture & DLP Regulation
Read original ↗
Reuters·2dRead more →
United States
▲

Rubrik Expands Project Hourglass With Code Guardian, Adds AHEAD, Trace3 and WWT

Rubrik announced the expansion of Project Hourglass, broadening its partner alliance to deliver Rubrik Code Guardian alongside Rubrik Agent Cloud. AHEAD, Trace3, and WWT joined the program, which already includes Cognizant, Deloitte, LTM, HCLTech, NTT DATA, and Wipro. Rubrik Code Guardian harnesses Anthropic's Claude Mythos 5 through a specialized security harness to evaluate code repositories against sophisticated, multi-step threat scenarios, testing a cloned, air-gapped copy of customer repositories rather than live production environments. According to Rubrik Zero Labs, 86% of cybersecurity and IT leaders anticipate that the proliferation of AI agents will outpace their organization's security guardrails within the next year. Rubrik Code Guardian is currently in private preview and accepting select design partners, and the company said it is not currently generally available and may change or be discontinued.
About megatrends
Cybersecurity & Digital Trust › Data Security & Cyber Resilience ▲Technology
Cybersecurity & Digital Trust › AI Security & Agent Guardrails ▲Technology
Cybersecurity & Digital Trust › Cyber Resilience & Ransomware Recovery Technology
RBRK · Technology · Positive Rubrik expanded Project Hourglass and launched Rubrik Code Guardian, a new AI-agent security product now in private preview with new partners AHEAD, Trace3, and WWT.
Read original ↗
Business Wire·2dRead more →
United StatesIsrael
▲

Core6 Partners with Armis from ServiceNow to Extend Exposure Management to Storage and Backup

Core6 announced a partnership with Armis from ServiceNow that integrates its StorageGuard storage security posture management platform with Armis' continuous asset intelligence, extending cyber exposure management to storage and backup systems. The integration correlates Armis' real-time asset intelligence with StorageGuard's authenticated vulnerability and misconfiguration findings for storage and backup systems, closing a gap that has left storage arrays and backup platforms outside exposure management programs. Core6 founder and CEO Gil Hecht said several banks the FSB classifies as globally systemically important harden their storage and backup with StorageGuard. Nadir Izrael, GVP of Cybersecurity and Risk at ServiceNow, said the partnership enables security teams to shift from reactive threat response to autonomous, AI-driven security. The integration is available immediately for existing Armis from ServiceNow and Core6 customers.
About megatrends
Cybersecurity & Digital Trust › Data Security & Cyber Resilience ▲Technology
Cybersecurity & Digital Trust › Data Security Posture & DLP ▲Technology
Cybersecurity & Digital Trust › Cyber Resilience & Ransomware Recovery ▲Technology
Core6 · Demand · Positive Core6's StorageGuard is integrated with Armis from ServiceNow, extending its storage security posture management to more customers.
Armis Security · Demand · Positive Armis' continuous asset intelligence is integrated with Core6's StorageGuard, expanding its cybersecurity platform's reach into storage and backup exposure management.
NOW · Demand · Positive Armis from ServiceNow partnership integrates Core6's StorageGuard, extending ServiceNow's exposure management offering to storage and backup systems.
Read original ↗
PR Newswire·2dRead more →
Thailand
▲

Synology survey finds 86% of Thai businesses prioritise AI-ready infrastructure, but only 9.5% are confident about cyber threats

Synology Inc. has released the findings of The Synology 2026 Southeast Asia Business AI Transformation Survey, which found that 86% of respondents in Thailand consider AI-ready infrastructure important for business operations and efficiency gains, though only 31.3% view it as very important. Meanwhile, 64.4% cited data security and privacy as the top obstacle to AI adoption, followed by data quality and availability at 47.3% and system deployment costs at 33.7%. On cyber risk, only 9.5% of respondents were highly confident their organisations are ready to handle AI-driven threats, while 38.5% said they are not ready. Although 92% of organisations already use data protection tools, only 21.4% are highly confident they could quickly recover systems from a ransomware attack and keep backup data secure, while 32.5% remain unsure they could restore data after an incident. Anthony Yang, Synology's head of Southeast Asia, said having a backup system alone is not enough and that data must actually be recoverable, and that organisations should separate backup systems from primary operating systems, along with safeguards to prevent backup data from being altered. The survey also found that 34% of Thai organisations still have no controls over employee use of AI, only 26.1% enforce controls through technical means, and 47.1% cannot see how external AI tools handle the data sent to them. At the Synology Press Event 2026, the company also presented the PAS7700, a high-speed storage system for mission-critical enterprise workloads, alongside ActiveProtect for backup and recovery management and the Synology Office Suite, as well as DSM Agent. It also disclosed a case study of Ethos Media Production, which adopted the PAS7700 as its central file storage hub with 70 terabytes of capacity, supporting 15 concurrent users and cutting the upload time for a 100-gigabyte video from about 40 minutes to just 2 minutes.
About megatrends
Cybersecurity & Digital Trust › Data Security & Cyber Resilience ▲Technology
Cybersecurity & Digital Trust › Cyber Resilience & Ransomware Recovery ▲Technology
Synology Inc. · Demand · Positive Synology's survey and press event showcase its AI-ready storage, backup, and Office Suite products, positioning it to capture demand from Thai businesses prioritizing AI infrastructure and data security.
Read original ↗
Kaohoon·2dRead more →