DEV Community

Ahsan Luqman
Ahsan Luqman

Posted on Originally published at aliasfleet.com on

110,000 Daiwa Clients' Data Possibly Leaked in Securities Vendor Breach

The breached server belonged to Scala Communications, Daiwa's inquiry vendor. On October 5, Daiwa said the intrusion may have leaked 110,000 clients' names, emails and account numbers. I run AliasFleet: one unique email address per site, so when a contractor's server is the one that gets hacked, you know exactly whose copy leaked.

Daiwa is Japan's second-largest brokerage. Scala is a Shibuya systems company that handles Daiwa's online customer inquiries. Somewhere between Friday night and Saturday morning, someone got into that server, and the inquiry history sitting on it included Daiwa client data. Daiwa's own systems were not touched.

What the vendor was holding

May have leaked Not at risk
Name Transaction access: the data alone cannot move money or place trades
Email address Daiwa's own systems, which were not breached
Securities account number
Inquiry records, including non-personal ones (about 220,000 records in total)

A note on the email addresses, because precision matters here. ITmedia, Nikkei Asia and NNN all list emails among the exposed data in their accounts of Daiwa's announcement. The Japan Times' rendering of the company's statement mentions names and account numbers. An inquiry-management server with no email addresses in it is hard to imagine, but the primary quote does not say the word, so I am marking the distinction instead of smoothing it over.

Twelve hours on a contractor's server

The intrusion ran roughly twelve hours, from 8:33 p.m. on October 2 to 8:01 a.m. on October 3, and though Scala told Daiwa the same day, the public announcement waited until October 5. Daiwa says it has taken emergency measures and is notifying the customers who may be affected, individually.

As of the announcement, there is no confirmed misuse, no confirmed public circulation of the data, and no inappropriate transactions. That is the current picture, not a promise. Twelve hours is enough time to copy an inquiry database many times over.

Your data's weakest custodian

This is the third time in a month the breach has come through the side door. Frontline Education lost school-district employee data through a third-party software product, and Quest Apartment Hotels leaked guest records through a third-party database operator. Now Daiwa through its inquiry vendor. The pattern is not subtle: the systems that hold your data are not the systems you signed up with.

You chose Daiwa. You did not choose Scala Communications, you have never heard of Scala Communications, and your emails sat on its server anyway. Every company you deal with has a Scala, a vendor with a copy of your details and its own security budget. You cannot audit them. You can only limit what you hand out in the first place.

An email plus an account number is a costume

Here is why this particular combination is nasty. A name and an account number turn a phishing email from generic spam into a message that knows who you are and where your money lives. Add the real email address, and the attacker does not need to guess where to send it. The lure writes itself: a message about your account, referencing a real inquiry you once made, from an address that looks almost right.

Daiwa is warning customers about exactly this: fraud calls and emails abusing names and inquiry details. The company will contact affected clients individually. Anyone who contacts you first, asking for passwords, PINs or card details, is not Daiwa.

If you are a Daiwa client

  1. Treat every unexpected contact about your account as hostile until proven otherwise. Call Daiwa through its official channels instead of clicking through.
  2. Daiwa is warning about fraud calls and mails that abuse names and inquiry details. Treat anyone asking for passwords, PINs or card details as a scammer; no legitimate company requests those by phone, email or text.
  3. Turn on multifactor authentication on your email account. Your inbox is the recovery path for your brokerage login, and the address is in this file.
  4. Check Have I Been Pwned once the breach is listed. It is the canonical place to see which of your addresses have leaked and where.
  5. You do not need to panic about your holdings: the exposed data cannot execute trades on its own, and no misuse has been confirmed. This one is about impersonation.

The breach-response guide has the full checklist in order.

The address you hand your broker

You cannot un-send the inquiry email. What you can do is make the next one traceable and killable in one click: give every company its own email alias. When the next vendor gets opened up, the address in the file belongs to that company alone. You pause it, the phishing dies, and the address itself tells you which vendor leaked, which is the leak-tracing mechanism doing exactly what it was built for.

If you have never used one: this is what an email alias is. The set-up guide takes about two minutes.

What I am watching for

Three things I am watching for: whether the investigation confirms the data was actually exfiltrated or only accessed; what the vulnerability at Scala was, because a twelve-hour window suggests something structural; and whether Japan's Personal Information Protection Commission gets a report, which would signal how seriously the regulator takes vendor-side exposure. If Daiwa confirms the exfiltration, names the vulnerability at Scala, or draws a regulatory response, this piece gets updated. Until then the takeaway stands: you cannot audit your broker's vendors, so hand each one an address you can kill.

Top comments (0)