Malware at Nippon Columbia puts 8.6 million Japanese karaoke customers' data at risk

Daiichi Kosho, operator of the Big Echo karaoke chain, says malware at data processor Nippon Columbia Group may have exposed records of 8.6 million customers and 93,000 employees.

Malware at Nippon Columbia puts 8.6 million Japanese karaoke customers' data at risk

At a glance

  • Nippon Columbia Group found malware on an employee's computer on October 5 and isolated the system on October 6.
  • About 8,631,000 customer and 93,000 employee records include names, gender, birth dates, emails and phone numbers.
  • Passwords are not included, and Daiichi Kosho says no data theft or leak has been confirmed so far.
  • Customers of Big Echo, Karaoke CLUB DAM and other brands are urged to watch for phishing attempts.

Daiichi Kosho, which describes itself as Japan's largest karaoke company, has warned that personal data of roughly 8.6 million customers and 93,000 employees may have been exposed after malware was found at Nippon Columbia Group (NCG), the company it outsources customer data handling to, according to BleepingComputer. The incident affects customers of several popular brands, including the Big Echo karaoke chain.

What happened

According to BleepingComputer, NCG informed Daiichi Kosho on October 5 that it had discovered malware on an employee's computer. NCG isolated the affected system the following day, on October 6. Daiichi Kosho published notices about the incident on its website, followed by an update on Friday, October 9, which BleepingComputer said did not add details about a possible data leak.

NCG is a Japanese entertainment group active in music, video and game software production and distribution, as well as artist management. Daiichi Kosho operates 521 karaoke venues, including the Big Echo chain. The company stressed that its own systems were not breached.

The report does not say what type of malware was involved, how the employee's computer was infected, or whether the malware spread to other systems. BleepingComputer said it found no public statement from NCG and had reached out to the company for comment.

What data is involved

The potentially exposed records cover about 8,631,000 customers and 93,000 employees. According to the company's disclosure as reported by BleepingComputer, the data includes:

  • Full names
  • Gender
  • Dates of birth
  • Email addresses
  • Telephone numbers

Passwords are not part of the affected data, and the company says it has seen no evidence of unauthorized use of loyalty points. Daiichi Kosho also said it has not confirmed any theft or leak of data so far, but it is advising customers to remain cautious.

Who is affected

The company said the incident may affect customers of BIG ECHO, MEGA BIG, Karaoke CLUB DAM, Banana Club, B-GARAGE and DK Dining. NCG has reset passwords and other authentication credentials and is investigating the cause and scope of the incident, including whether any of the data has appeared online.

What to do

Even without passwords, a combination of names, birth dates, emails and phone numbers is valuable for targeted phishing and phone scams. Daiichi Kosho advises customers to treat unsolicited emails, text messages and phone calls requesting payments or sensitive personal or financial information with suspicion. Affected customers should avoid clicking links in unexpected messages that reference their karaoke memberships, and should verify any request directly through the company's official channels.

The case is another example of how a single compromised endpoint at an outsourced data processor can put millions of customer records at risk, highlighting the importance of vendor security oversight.

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.