Menu
Browse
Date:

Mar 2023

Location:

Japan

Summary

A Fukuoka-based organization combating organized crime experienced unauthorized remote access to staff computers after an employee responded to a fraudulent "security update" message, enabling external control for approximately 20 minutes. This incident potentially compromised names and phone numbers of roughly 3,500 individuals who had sought advisory services from the Center. Officials acknowledged the possibility of data leakage and publicly cautioned against suspicious communications falsely claiming affiliation with the institution, issuing an apology for the security lapse.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On March 20, 2023, the Fukuoka Prefecture Violence Elimination Movement Promotion Center, a public interest incorporated foundation in Fukuoka City focused on eliminating organized crime, disclosed a cybersecurity incident involving unauthorized remote access to staff computers. During routine operations, a staff member encountered a message labeled "security update" on their computer screen, prompting them to contact a provided phone number. The individual who answered the call instructed the staff member to perform actions that resulted in the computer being remotely controlled by an external party. This unauthorized access persisted for approximately 20 minutes before the connection was terminated. The center confirmed the incident occurred on the same day it was reported and initiated an immediate internal review.

Cyber Incident Image

The breach potentially exposed personal information of approximately 3,500 individuals, including names and telephone numbers of people who had sought advice from the center. While the exact scope of data exfiltration remained unconfirmed, the organization publicly acknowledged the possibility of external leakage. Yoshinobu Onoe, the center’s executive director, issued a formal apology to affected individuals and Fukuoka Prefecture residents, emphasizing regret over the incident. The center advised vigilance against suspicious communications, specifically phone calls or emails falsely claiming affiliation with the organization. No technical details about remediation efforts or forensic findings were disclosed in the initial announcement. The incident highlighted operational vulnerabilities in an entity tasked with combating criminal activities, though no further impacts on ongoing anti-violence initiatives were described.

Sources
Sources available to members
1 source