Casio confirms data theft after Underground ransomware attack
- Organization
- Casio Computer Co., Ltd.
- Exploit
- Ransomware
- Industry
- Consumer Electronics
Casio Computer Co. said an unauthorized party accessed its servers on October 5, 2024 and deployed ransomware, damaging systems and causing a partial outage across some of its services. In a notice published on October 11 the company confirmed that personal information and internal documents had been leaked.
Casio said the exposed material covered personal details of employees, including temporary and contract staff, of business partner contacts, of job applicants and of customers of certain services. Internal documents relating to contracts, invoices, sales, legal matters, finance and technology were also involved. The company said the CASIO ID and ClassPad.net platforms ran on separate systems and were unaffected, and that no credit card information was exposed because its online sales channels do not store card data.
The Underground ransomware group claimed responsibility and published stolen files on its leak site, according to BleepingComputer. Casio notified Japan's Personal Information Protection Commission and the police, and asked the public not to circulate the leaked material in order to limit secondary harm to those affected.
At the time of reporting Casio had not quantified the exposure. Its concluding investigation, published in January 2025, put the total at 8,478 individuals: 6,456 employees, 1,931 business partner contacts and 91 customers. Casio said it found no evidence of theft from its customer database and attributed the intrusion to weaknesses in its defenses against phishing email and in its global network security.