Cyber & AI intelligence
Wasteland.
Briefs indexed2988
Issues30
Published Mondays07:30 CT
▣ Breach DAI-ICHI-LIFE 2026-10-03

Dai-ichi Life: HR System Breach Exposes Data on 120,000 Current and Former Staff

"Dai-ichi Life Group (第一ライフグループ) and its core subsidiary Dai-ichi Life Insurance (第一生命保険) said on October 2, 2026 that an unauthorized third party broke into the HR system the two companies share. Personal data on about…"

Dai-ichi Life Group (第一ライフグループ) and its core subsidiary Dai-ichi Life Insurance (第一生命保険) said on October 2, 2026 that an unauthorized third party broke into the HR system the two companies share. Personal data on about 120,000 people may have been viewed and taken: roughly 50,000 current employees and 70,000 former employees. Retention is unusually long. Former office staff who left as far back as 1967 are included, so the exposed records reach back nearly 60 years. Every report reviewed says customer and policyholder data has not been found to be affected so far. The companies have not said how the attackers got in. One caveat on sourcing: the companies' own notice is not in the source set for this brief. The details below come from Japanese press and security outlets that report on that notice, and they agree on every key figure.

What Happened

Japan Cyber Watch, Security Measures Lab (rocket-boys.co.jp) and RealTime News NAVI all give the same timeline:

That is eight days between detection and disclosure. RealTime News NAVI quotes the companies apologizing for "the great concern and inconvenience" caused to former employees. Security Measures Lab reports that the group has promised to publish further facts as they come to light.

RealTime News NAVI also notes that Dai-ichi Life Group took that name in April 2026, when it changed its trade name from Dai-ichi Life Holdings. Older records and third-party profiles still use the former name.

The group's investor-relations news pages (English and Japanese) did not list a breach notice when they were captured, with the latest entries dated September 16 and September 3. That fits a notice aimed at affected individuals rather than one filed as a market disclosure. It should not be read as a sign the notice is missing.

FNN reports that no secondary damage, such as fraud or phishing using the leaked data, has been confirmed so far. RealTime News NAVI and Security Measures Lab say the same.

What Was Taken

Volume. All outlets agree on about 120,000 people in total. Japan Cyber Watch gives the most detailed breakdown:

Group Approx. number
Current office staff 13,000
Current sales staff 37,000
Former employees 70,000
Total 120,000

FNN and the other Japanese outlets give only the top-level split of about 50,000 current and 70,000 former employees, which matches Japan Cyber Watch. RealTime News NAVI calls 120,000 a maximum ("最大約12万人") and says the current-employee figure is an approximate count taken from press reports.

Who is in scope. Former employees are included if they were:

Staff seconded from either company to group companies are also included. Japan Cyber Watch names Dai-ichi Frontier Life and Dai-ichi Neo Life as examples.

Data fields. RealTime News NAVI and Security Measures Lab list nine fields:

Japan Cyber Watch and FNN give shorter lists that are subsets of these nine. None of the sources mention bank details, national ID (My Number), salary or health data.

Not affected (so far). Every source says customer and policyholder data has not been found to be accessed. Security Measures Lab stresses that the 120,000 figure counts employees, not insurance customers or policy records.

Why It Matters

Organizational data makes social engineering easier. A list of names with home addresses is bad enough. This one also links each person to their department, title, role and manager, which amounts to a usable org chart for one of Japan's largest life insurers. RealTime News NAVI warns that the data could be used for messages impersonating colleagues or business partners. Pretexting, business email compromise and fake "HR" or "pension" contact aimed at former staff are the obvious follow-on risks.

Retention was the biggest factor. More than half of the affected people are former employees, and some left almost six decades ago. Security Measures Lab notes that Dai-ichi Life's privacy policy allows employment data to be kept after people leave where it is needed for personnel and labor management. It argues that long retention is what pushed the impact back into past generations of staff. Former staff did not choose to stay in this system, and many will not expect contact from their old employer.

The sales force is a phishing target. About 37,000 current sales staff are in the data. Life insurance sales staff deal directly with policyholders, so an attacker who knows a salesperson's name, branch and manager could impersonate them convincingly to customers. Customer data was not reported as taken, but customers could still be reached through this route.

Regulatory clock. RealTime News NAVI notes that under Japan's Act on the Protection of Personal Information (APPI), a leak involving more than 1,000 people that may have been caused with improper intent, such as unauthorized access, must be reported to the Personal Information Protection Commission (PPC). A detailed report is generally due within 60 days of discovery. That is the outlet's reading of the law. No source confirms that a filing has been made.

Wider pattern. The breach follows weeks after Japan's Digital Agency disclosed on September 11, 2026 that its GSS platform had been breached and about 246,000 records, mostly belonging to officials and contractors, may have been taken. ThreatPaper reports that the GSS attacker got in through a known, published flaw in a VPN appliance and then used a contractor's account. Nothing in the sources links the two incidents. They are mentioned together only because both put large staff (not customer) datasets at major Japanese organizations at the center of a breach.

The Attack Technique

Unknown. The companies have described the cause only as "unauthorized access by a third party" (第三者による不正アクセス). As of October 2, Japan Cyber Watch, RealTime News NAVI and Security Measures Lab all report that:

The reports say data "may have been viewed and leaked" (閲覧・流出したおそれ). That wording suggests the companies have not yet confirmed that data actually left their network, or how much. Until the companies say more, treat theories about the entry point, including a VPN or contractor path like the GSS case, as speculation.

What Organizations Should Do

  1. Audit how long HR data is kept. Check how far back records of former employees go. If there is no legal or operational reason to keep someone's home address 20 or more years after they left, delete it or move it to an offline archive that cannot be queried. Security Measures Lab makes this point directly, and it is the main lesson from this incident.
  2. Restrict access to the HR system. Only the people who need it should be able to query current and historical staff records, and exports should require a separate approval. Review service and contractor accounts with the same scrutiny as staff accounts.
  3. Monitor for mass reads and exports. Alert when one account or session reads or exports an unusual number of employee records. In the Digital Agency case, mass file access was the first sign of the intrusion. HR systems should have the same monitoring.
  4. Separate HR data from other systems. Keep HR systems isolated from general corporate networks and customer platforms, with their own authentication and network boundaries. That is one plausible reason, though unconfirmed, why Dai-ichi's customer data appears unaffected here.
  5. Plan for phishing that uses leaked org-chart data. Tell current and former staff, and in sales-led businesses customers too, that messages may arrive using real names, titles and manager names. Require out-of-band verification for payment changes, credential resets and requests that appear to come from HR.
  6. Write notification plans that cover former employees. Many of them will have moved or changed contact details. Have a channel ready to reach them, such as a dedicated hotline or a public notice like the one Dai-ichi addressed to former staff.

Sources: Dai-ichi Life Breach: HR Data on 120,000 Current and Former Staff,... | 第一ライフグループに不正アクセス 12万人分の情報流出か(FNNプライムオンライン)|dメニューニュース(NTTドコモ) | 第一ライフグループで情報漏えいか 社員・退職者12万人が対象 - リアルタイムニュースNAVI | IR News (FY2026) Daiichi Life Group, Inc. | IRニュース(2026年度) 株式会社第一ライフグループ | 第一生命に不正アクセス、従業員ら約12万人分の個人情報が漏えいした可能性-退職者約7万人も対象セキュリティニュースのセキュリティ対策Lab | Fred S. | Japan Digital Agency GSS breach: a known VPN flaw, a contractor acc...