Iseto Corp hit with ransomware attack data breach
Take action: This is why deleting data should be fully complied with. A subsequent data breach exposing data that was supposedly deleted can have serious reputational and legal consequences when organizations don't comply to their commitments of data deletion.
Learn More
Iseto Corp., a Kyoto-based printing and mailing service provider, has been hit by a ransomware attack, exposing at least 900,000 pieces of personal information, much of it data of the prefecture and municipalities.
Founded in 1855, Iseto began as a paper wholesaler and retailer before expanding into information processing services in the 1970s.
It was revealed that sensitive personal data, supposedly deleted post-contract, was still accessible on Iseto's internal network, violating data handling protocols and were stolen in the attack.
Although the total number of affected individuals is not disclosed, approximately 145,000 individuals from Tokushima Prefecture and around 420,000 people from Toyota, Aichi Prefecture are affected, as well as residents from Kyoto Prefecture, Tokyo’s Ota Ward, Wakayama, Takamatsu, and Hiratsuka in Kanagawa Prefecture.
The ransomware gang 8Base listed Iseto as a victim on their dark web site. Exposed data types:
- Names
- Addresses
- Tax amounts
- Vehicle license plate numbers
The ransomware attack has drawn criticism for Iseto's inadequate response, including the initial denial of any data breach.
Iseto Corp. has pledged to provide details of the cyberattack as the investigation progresses.