CSIDB logo
Incident

WDB Holdings

Incident posture

Attack window
Aug 2022
Location
Japan
Status
Historical
CIA posture
Available to members
Updated
2025-10-17 00:00

Linked entities

Victim
WDB Holdings
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Aug 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

WDB Holdings experienced a ransomware attack disrupting access to its mail systems and file servers, prompting suspension of internal network operations. The company prioritized recovery efforts and internal investigations while confirming no evidence of personal information leakage. External specialists were engaged to assess intrusion vectors and scope of damage, with findings to be communicated upon completion.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On August 1, 2022, WDB Holdings Co. Ltd. experienced a disruption preventing access to its group IT system’s mail system and file servers. The company confirmed on August 2 that the incident stemmed from a ransomware attack conducted by a third party, leading to the immediate suspension of internal network operations. WDB Holdings publicly apologized for inconveniences caused to customers and related parties, acknowledging delayed public notification due to prioritizing recovery efforts. The company’s information system department initiated recovery procedures and launched an internal investigation into the attack’s origin. No evidence of personal information leakage or other data exfiltration was identified during the initial assessment.

WDB Holdings announced plans to engage an external IT specialist firm to collaborate with its internal team on determining the intrusion vector and full scope of damage. The company committed to disclosing investigation findings upon completion while maintaining suspended network operations during remediation. Business disruptions were confined to internal mail and file server accessibility, with no confirmed compromise of customer or third-party data. Recovery timelines and specific ransomware variants involved were not disclosed in the August 2 statement. WDB Holdings reiterated apologies for operational impacts and assured stakeholders of ongoing efforts to restore systems securely.

Sources

Sources available to members: 1 source.

CSIDB