Cyber & AI intelligence
Wasteland.
Briefs indexed3012
Issues30
Published Mondays07:30 CT
▣ Breach DAIWA-SECURITIES-C 2026-10-05

Daiwa Securities: Vendor Server Breach May Have Exposed Data on 110,000 Clients

"Daiwa Securities Group, Japan's second-largest brokerage, disclosed on October 5, 2026 that customer data may have been taken from a contractor's server. The contractor, Scala Communications Inc., runs the online…"

Daiwa Securities Group, Japan's second-largest brokerage, disclosed on October 5, 2026 that customer data may have been taken from a contractor's server. The contractor, Scala Communications Inc., runs the online customer inquiry system for Daiwa's brokerage unit. Kyodo, Nikkei Asia and ASCII.jp all report that the exposed data includes the names, email addresses and securities account numbers of about 110,000 customers. They also report around 220,000 affected records in total once inquiry records without personal identifiers are counted. Briefs.co and Investing.com describe the figure as "up to" 110,000. No source gives a different count. Note that none of the eight sources is a primary document such as Daiwa's own notice or a regulator filing. Everything below relies on press accounts of the company's statement. Daiwa says its own systems were not breached and it has found no fraudulent transactions.

What Happened

Kyodo (via Nikkei Asia) says the unauthorized access happened between Friday evening and Saturday morning. BigGo Finance and ASCII.jp give a more exact window: roughly 8:33 p.m. on October 2 to 8:01 a.m. on October 3. That is a dwell time of about 11.5 hours. The intrusion hit infrastructure run by Scala Communications, which Daiwa used to manage customer inquiries sent over the internet.

Scala told Daiwa on Saturday, October 3 that it had found evidence of unauthorized access and a possible leak (BigGo, Briefs.co). Daiwa made the incident public on Monday, October 5. BigGo and Investing.com report that Scala has put emergency security measures in place and that Daiwa is still working out how much data was exposed.

Every outlet says the same thing about confirmation: Daiwa has not confirmed that any of the data was published or spread online. The disclosure is worded as a "possible" leak, not confirmed theft. Briefs.co and Investing.com report that Daiwa shares wiped out earlier gains and fell almost 1% in Tokyo afternoon trading.

What Was Taken

The affected data lived on the inquiry management server. According to the reporting, it includes:

About 110,000 records contain personal data. The rest of the roughly 220,000 records are inquiry data that does not identify individuals. Daiwa says the data alone cannot be used to log in to securities accounts or place trades, online or otherwise. No source mentions passwords, PINs, government ID numbers or financial balances.

The account numbers are still sensitive. When an attacker can combine a name, an email address, a real account number and the topic of a past support request, they have what they need for convincing impersonation.

Why It Matters

This is another case of third-party exposure. The attacker did not need to get into the brokerage, only into a customer-service vendor that held brokerage data. Daiwa's statement that its own systems were not breached is probably true, and it changes little for affected customers.

It also fits a regional pattern. Briefs.co and Investing.com put it alongside recent unauthorized access incidents at Yamato Holdings and Sakura Internet in Japan. They also note that South Korean authorities ordered financial institutions to run security checks after a run of bank data breaches.

The main risk now is follow-on fraud. Customer-support data sits with vendors that have weaker controls than the financial firms they serve, yet it carries the context social engineers need. A phishing email that mentions an inquiry the customer really sent is far more believable than a generic lure.

The Attack Technique

No source has disclosed how the attackers got in. Neither Daiwa nor Scala has said publicly which vulnerability, credential or access path was used. No threat actor has been named, and as of October 5 no group has claimed the attack or posted a leak. The confirmed facts are limited to:

Readers should not take the "hack" label in headlines as evidence of any specific technique until Scala or Daiwa releases forensic findings.

What Organizations Should Do

  1. Inventory what vendors hold, not just what they can reach. Map which third parties store customer data, including support tickets, inquiry forms and CRM exports, and how long they keep it.
  2. Minimize data in support platforms. Inquiry systems rarely need full account numbers. Mask or tokenize identifiers in vendor-hosted tools and set aggressive retention limits on old tickets.
  3. Require vendor detection and notification SLAs. Scala found and reported this within hours. Contracts should require that speed, plus logging, off-hours monitoring and the right to forensic evidence.
  4. Get ahead of phishing. If a vendor holding contact data is breached, warn customers right away and tell them plainly what you will never ask for. Daiwa told customers never to share transaction IDs, passwords, PINs or one-time passwords.
  5. Watch for impersonation infrastructure. Look for lookalike domains, spoofed sender addresses and fake call-center numbers aimed at affected customers in the weeks after disclosure.
  6. Tighten account-level controls for exposed users. Flag affected accounts for extra authentication checks and anomaly monitoring, even when the leaked data alone cannot be used to trade.

Sources: Daiwa Securities' customer info leak may have come from hack - Nikk... | Daiwa Securities Says Unauthorized Access at Vendor May Have Expose... | Daiwa Vendor Hack May Have Exposed 110,000 Clients | Acciones de Daiwa caen tras hackeo que expone datos de 110,000 clie... | Scott Traer | Daiwa Securities Reports Possible Leak of ~110,000 Customer Records... | Akcje Daiwa spadają po wycieku danych 110 000 klientów Przez Investing | Daiwa Securities' customer data may have leaked due to unauthorized...