Skip to content
Daiwa Securities Says Unauthorized Access at Vendor May Have Exposed ...

Daiwa Securities Says Unauthorized Access at Vendor May Have Exposed ...

Finance.Biggo • October 5, 2026

Daiwa Securities Group (8601.T) announced on October 5 that a server operated by an external company entrusted with managing internet-based customer inquiries for its subsidiary Daiwa Securities was subject to unauthorized access, potentially exposing approximately 220,000 records, including information that cannot identify individuals. Of these, roughly 110,000 contain personal information such as names, email addresses, and securities account numbers.

The unauthorized access targeted Scala Communications, a systems company contracted to provide inquiry management services. Intruders gained access to the company's servers from approximately 8:33 p.m. on October 2 to 8:01 a.m. on October 3. Daiwa Securities received notification from the company on October 3. Scala Communications has already implemented emergency security enhancements, and no additional unauthorized access or data leakage has been confirmed at this time.

No unauthorized access to Daiwa Securities' own systems has been confirmed, and the company stated that the potentially leaked information alone is insufficient to access securities accounts or conduct online transactions. As of October 5, no fraudulent transactions attributable to this incident, nor any public disclosure or dissemination of the information on the internet, have been confirmed.

Timeline of the Unauthorized Access

The unauthorized access spanned approximately 11 and a half hours from the night of October 2 to the morning of October 3, and was publicly disclosed two days after the vendor reported it. The timeline presented in the announcement is as follows.

Customer Response and Warnings

Daiwa Securities indicated it will potentially affected customers individually. The company also cautioned that names and inquiry details could be misused in phishing emails or suspicious phone calls impersonating Daiwa Securities or other entities, urging customers never to provide trading IDs, passwords, PINs, or one-time passwords.

Breakdown of the Leak Scale

The breakdown of information potentially leaked in this incident is as follows.

Note: Personal data includes names, email addresses, securities account numbers, and other details.

Reporting and Notification Requirements Under Japan's Amended Personal Information Protection Act

Japan's amended Act on the Protection of Personal Information, which took effect in April 2022, mandates reporting to the Personal Information Protection Commission and notification to affected individuals when a personal data breach occurs and there is a risk of harm to individuals' rights and interests. Reporting is required when any of the following applies: the breach involves special care-required personal information, there is a risk of financial damage, the breach was carried out with malicious intent, or personal data of more than 1,000 individuals was leaked.

Reporting to the commission is a two-stage process: an initial report within approximately 3 to 5 days of becoming aware of the incident, followed by a final report within 30 days (or 60 days if malicious intent was involved). Notification to affected individuals must promptly convey the leaked data items, the cause, and information in a manner that is easy for the individual to understand.

This incident involves personal information of approximately 110,000 individuals and resulted from external unauthorized access. The scale exceeds the 1,000-person threshold that triggers reporting requirements under the amended law, and Daiwa Securities has announced it will potentially affected customers individually.

Vendor-Targeted Attacks on Financial Institutions

Financial institutions are increasingly outsourcing portions of their operations to external vendors, and attacks exploiting vulnerabilities in vendor security systems have been reported with growing frequency both domestically and internationally in recent years. This incident also targeted a vendor server managing inquiry data, rather than Daiwa Securities' own systems.

Scala Communications, the target of this attack, is a wholly owned subsidiary of Scala (4845), a company listed on the Tokyo Stock Exchange Standard Market that provides SaaS/ASP services for enterprises. According to Scala's securities report for the fiscal year ended June 2026, Scala Communications generated revenue of approximately ¥3.3 billion (approximately $20.9 million), accounting for more than 10% of Scala's consolidated revenue.

Daiwa Securities has explained that the potentially leaked information alone is insufficient to conduct transactions, and the risk of direct financial loss is considered low. However, if names, email addresses, and account numbers are leaked, there remains concern that the combined information could be exploited for targeted phishing attacks. The company's issuance of warnings reflects vigilance against such secondary damage.

Japan's Financial Services Agency requires financial institutions to thoroughly manage their vendors, and this incident may prompt peer firms to re-examine their vendors' security arrangements.

Following Daiwa Securities' announcement at noon on October 5, shares of Daiwa Securities Group (8601.T) turned negative in the afternoon session on the Tokyo Stock Exchange.

Once added, BigGo Finance appears first in Google Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.

Extracted Entities

Attack Types (1)

Countries (1)

Industries (1)