Cyber Incident Victim: Toshiba Tec Corp
Date:
May 2021
Location:
France
Summary
A Toshiba unit fell victim to the DarkSide ransomware group, known for the Colonial Pipeline attack, impacting its French subsidiary and prompting network shutdowns between Japan, Europe, and subsidiaries to contain the breach. The company engaged third-party forensic experts to investigate potential data leaks, with DarkSide affiliates claiming theft of over 740GB of data including passport scans and project documents, though the organization reported minimal work data loss. The ransomware-as-a-service group's leak site temporarily became inaccessible, while cached evidence suggested significant data exfiltration amid broader warnings from U.S. agencies about DarkSide operations.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On May 13, 2021, DarkSide ransomware operators targeted Toshiba Tec Corporation, a Toshiba subsidiary specializing in barcode scanners, point-of-sale systems, printers, and electrical equipment. The attack primarily affected the company’s French subsidiary. Upon detecting the intrusion, Toshiba Tec immediately disconnected networks linking its operations in Japan, Europe, and other global subsidiaries to contain the infection and prevent lateral movement. The company activated recovery protocols and restored systems using backups while initiating an internal investigation to assess the breach’s scope. Third-party cybersecurity forensic experts were engaged to assist in analyzing the attack vector, data exposure, and operational impact. Toshiba Tec publicly stated only a "minimal amount of work data" was permanently lost due to the incident, though it acknowledged the possibility of external data leaks by the attackers.

DarkSide affiliates claimed responsibility for the attack, alleging theft of over 740GB of data, including passport scans, project documents, and corporate presentations. Evidence from a cached DarkSide leak post, accessed via Kela’s Darkbeast search engine, corroborated these claims, though Toshiba Tec did not confirm external dissemination of customer data. The incident occurred days after DarkSide’s high-profile attack on Colonial Pipeline, which disrupted U.S. fuel distribution and prompted FBI and CISA advisories on the group’s ransomware-as-a-service model. Toshiba Tec maintained operations during network isolation but faced potential reputational and legal risks from the exposure of sensitive employee and corporate documents. The company continued forensic analysis to determine data exfiltration timelines and whether critical infrastructure or customer systems were compromised.
