CSIDB logo
Incident

Atsugishi Fishery Cooperative Association

Incident posture

Attack window
Jun 2022
Location
Japan
Status
Historical
CIA posture
Available to members
Updated
2026-02-08 02:07

Linked entities

Victim
Atsugishi Fishery Cooperative Association
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jun 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Atsugishi Fishery Cooperative Association experienced a malware attack involving Emotet, compromising customer data from its mail-order site. An infected computer used by the direct sales store potentially exposed emails containing names, addresses, telephone numbers, and email addresses exchanged between the cooperative and customers. The incident led to the temporary closure of the affected mail-order platform while recovery efforts were undertaken, with operations scheduled to resume following security remediation. No additional details regarding the intrusion method or broader operational disruptions were disclosed.

Motives

Detailed motive labels are available to members.

3 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

The Atsugishi Fishery Cooperative Association experienced a malware incident in June 2022 involving its mail-order store, Auroko. The cooperative identified that one computer used by the direct sales store had been infected with the Emotet malware. This infection potentially resulted in the leakage of stored mail data to external parties. The compromised data included emails exchanged between the store and its customers, containing personal information such as names, addresses, telephone numbers, and email addresses. The malware’s presence was confirmed through internal discovery processes, though the exact date of initial infection was not publicly disclosed. The cooperative did not specify how the malware was detected but acknowledged the breach’s potential scope involving customer communications.

In response to the incident, the cooperative took immediate action by suspending operations of the affected mail-order site. The closure remained in effect until a scheduled reopening date of August 12, 2022. The organization did not disclose whether forensic analysis confirmed actual data exfiltration or merely assessed the risk of leakage. No information was provided regarding containment measures beyond isolating the infected terminal or whether law enforcement was involved. The incident’s primary impact centered on potential unauthorized access to customer correspondence and personal data, though the cooperative did not report evidence of misuse. Service restoration efforts focused on ensuring system security before resuming operations, with no mention of customer notifications or external cybersecurity partnerships in the available disclosures.

Sources

Sources available to members: 1 source.

CSIDB