vz-risk / VCDB

VERIS Community Database
Other
578 stars 180 forks source link

Yakult Australia confirms 'cyber incident' after 95 GB data leak #20300

Closed swidup closed 2 weeks ago

swidup commented 10 months ago

https://www.bleepingcomputer.com/news/security/yakult-australia-confirms-cyber-incident-after-95-gb-data-leak/

https://www.techradar.com/pro/security/yakult-australia-sees-a-major-user-data-leak

etgifford commented 2 weeks ago

https://kirbyidau.com/2023/12/28/incident-yakult-australia-targeted-in-cyber-attack-employee-files-published-on-dark-web-abc-news-australia/ https://www.mi-3.com.au/10-01-2024/cybersecurity-breaches-hit-inspiring-vacations-and-yakult-australia

etgifford commented 2 weeks ago

JSON: 956f005e-c6c3-481d-b2a5-39458e47ec5c, Yakult Australia (subsidiary of Yakult Honsha Co), HQ: Melbourne, Australia, EMP: , NAICS: 311511 (Fluid Milk Manufacturing). A ransomware attack was discovered on December 15, 2023, when staff were locked out of their computers and messages appeared on screens reading “YOU HAVE BEEN PWND”. DragonForce (Malaysia) successfully breached Yakult Australia’s Australian and New Zealand networks. DragonForce leaked 95.19 GB of data on its onion leak site, DragonLeaks, on Dec 20, 2023. The hackers threatened to publish more files if Yakult Australia did not pay a ransom, and directed them to an address on the dark web for instructions on how to recover the files. The exfiltrated files contained several business documents, spreadsheets, credit applications made by Yakult Australia, employee records, passports, salaries, driver’s licenses, pre-employment medical assessments, and performance reviews. Some of the files date back to 2001. A separate database also contains the names and addresses of nearly 9,000 people. Yakult released a statement to customers Dec 23, 2023 notifying them of the attack.