Cyber Incident Victim: 積水ハウス株式会社
Date:
Jan 2022
Location:
Japan
Summary
A cybersecurity incident involving Sekisui House Co., Ltd. stemmed from Emotet malware infections affecting some group computers, enabling fraudulent emails impersonating employees to be sent to external contacts. The spoofed messages displayed legitimate employee names but originated from non-corporate email domains, with attachments or embedded links posing risks of further malware infections or unauthorized access if opened. The company acknowledged the disruption caused, confirmed blocking suspicious emails as part of existing security measures, and committed to strengthening information security protocols to prevent recurrence.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
In early January 2022, Sekisui House Group confirmed a cybersecurity incident involving Emotet malware infections affecting a subset of its corporate computers. The compromise enabled threat actors to send fraudulent emails impersonating Sekisui House Group employees to multiple external parties who had previously corresponded with the company. These spoofed messages displayed legitimate employee names in sender fields but originated from non-company email domains distinct from Sekisui House's official sekisuihouse.co.jp addresses. The malicious emails contained attachments in Microsoft Office formats (Excel and Word) and embedded hyperlinks designed to propagate malware or enable unauthorized system access if activated. The company publicly acknowledged the incident on January 28, 2022, issuing apologies for the inconvenience and anxiety caused to customers and business partners affected by the campaign.

Sekisui House responded by implementing measures to block suspicious emails across its systems while reinforcing existing antivirus protections. The organization emphasized ongoing efforts to enhance information security protocols following the breach, though specific technical containment procedures remained undisclosed. No evidence suggested systemic data exfiltration or operational disruption beyond the email-based threat vector. The primary documented impact involved reputational harm and trust erosion stemming from the impersonation campaign, necessitating public advisories about identifying spoofed communications. Recovery efforts focused on preventing further propagation through user awareness directives urging recipients to delete suspicious messages unopened rather than interacting with attachments or links. The company committed to strengthening defensive controls against similar threats without detailing specific security upgrades or forensic findings.
