Cyber Incident Victim: Bandai Namco Holdings Inc.
Date:
Jul 2022
Location:
Japan
Summary
A cybersecurity incident involving unauthorized access to internal systems at multiple Asian subsidiaries of Bandai Namco Holdings was detected, prompting immediate containment measures including server access blocking. The breach potentially exposed customer information related to the company's Asian toy and hobby business operations outside Japan, though the extent of data compromise remains under investigation. The organization is collaborating with external experts to determine the scope of impact, identify root causes, and implement enhanced security measures to prevent recurrence while continuing forensic analysis.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 4 techniques |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On July 3, 2022, Bandai Namco Holdings Inc. detected unauthorized third-party access to internal systems at multiple group companies across Asia, excluding Japan. The breach targeted servers and computers containing customer information related to the company's Asian toy and hobby business operations outside Japan. Upon discovery, the company implemented immediate containment measures, including blocking access to affected servers to prevent further compromise. Bandai Namco initiated forensic investigations to determine the scope of potential data exposure, whether any customer information was exfiltrated, and the root cause of the intrusion. The incident did not impact the company's domestic Japanese operations, with the breach confined to specific regional subsidiaries.

Bandai Namco engaged external security partners to assist with the ongoing investigation while maintaining business continuity measures across unaffected systems. The company acknowledged the possibility of customer data compromise but did not disclose specific data types, record volumes, or confirmed exfiltration at the time of reporting. No ransomware deployment or operational disruption beyond access restrictions was reported. Bandai Namco publicly apologized for causing concern to stakeholders and committed to providing updates as the investigation progressed. The organization pledged to strengthen group-wide cybersecurity defenses through external partnerships and internal policy enhancements to prevent recurrence.
