Nippon Columbia Malware Incident May Expose Data of 8.7 Million Karaoke Customers and Employees
Daiichi Kosho, a major Japanese entertainment systems manufacturer, has revealed that a malware infection at its contractor, Nippon Columbia, may have exposed more than 8.7 million customer and employee records.
Malware found on Nippon Columbia employee computer
Daiichi Kosho is Japan’s largest karaoke manufacturer and has 521 karaoke venues nationwide, including the Big Echo chain, one of the country’s most popular karaoke box chains.
Daiichi Kosho entrusts the handling of customers’ personal information to Nippon Columbia Group (NCG), a Japanese entertainment group whose businesses include producing and selling music, video, and game software, as well as artist management.
Nippon Columbia notified Daiichi Kosho on October 5 that it had discovered malware on an employee’s computer. The affected systems were quarantined the following day.
Daiichi Kosho said that no data theft or leakage has been confirmed. However, the company has advised customers to remain cautious because of the potential risks.
More than 8.7 million records potentially affected
The company said the potentially affected data includes records for 93,000 employees and 8,631,000 customers. The information may include:
- Full names
- Sex
- Dates of birth
- Email addresses
- Telephone numbers
The incident may affect customers of Big Echo, Mega Big, Karaoke CLUB DAM, Banana Club, B-GARAGE, and DK Dining.
No passwords or fraudulent loyalty-point activity reported
Daiichi Kosho said the affected data does not include passwords and that there is no evidence that loyalty points were used fraudulently.
The company also said its own systems were not compromised. NCG has reset passwords and other authentication credentials while investigating the cause and scope of the incident, including whether any data was leaked online.
Customers should be cautious of unsolicited emails, SMS messages, or phone calls requesting payment or sensitive personal or financial information.
Daiichi Kosho provides limited additional information
In an update posted Friday, Daiichi Kosho said it would not provide additional information about the potential data breach.
BleepingComputer was unable to find public information from NCG about the security incident. We have contacted the company for more information and are awaiting a statement.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



