Cyber Incident Victim: Fujikura Ltd.
Date:
Jan 2023
Location:
Thailand
Summary
A Japanese multinational corporation experienced unauthorized third-party network access at its Thai subsidiary, prompting immediate containment measures including disconnecting affected devices and networks to prevent further spread. The company engaged external cybersecurity experts to investigate the breach's scope and restore operations, while issuing a public apology for the disruption caused. The organization committed to strengthening its information security protocols and implementing preventive measures against future incidents.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On January 12, 2023, Fujikura Ltd.'s Thailand-based group company experienced unauthorized third-party access to its network systems. The intrusion was detected by the organization, though the specific method of initial detection remains undisclosed in public statements. Upon confirming the breach, Fujikura implemented immediate containment measures by disconnecting all compromised devices and affected network segments from external connections. This rapid isolation aimed to prevent lateral movement of the threat actor within corporate systems and mitigate potential damage propagation. The company engaged external cybersecurity specialists to assist with forensic analysis and recovery operations, though the identity of these third-party responders was not specified in official communications.

The incident caused operational disruptions at the Thai subsidiary, though Fujikura's disclosure did not quantify the duration or specify affected business functions. No details were provided regarding whether data exfiltration occurred, what systems were targeted, or whether customer or employee information was compromised. Fujikura publicly apologized for the inconvenience and concern caused to stakeholders, acknowledging the breach's impact on business continuity and trust. Recovery efforts focused on determining the full scope of infiltration while restoring secured systems, with no specified completion timeline provided in the initial announcement. The company committed to strengthening group-wide information security measures and implementing additional safeguards to prevent recurrence, without elaborating on specific technical or organizational changes planned.
