Mizuno USA said attackers spent two months copying files from its network

Organization
Mizuno USA
Exploit
Ransomware
Industry
Manufacturing

Mizuno USA, the Georgia-based arm of the Osaka sporting goods maker Mizuno Corporation, began notifying people on January 30, 2025 that their personal information had been taken during an intrusion the previous year. The company filed a breach notice with the Maine Attorney General's office at the same time.

According to the notification, an unauthorised party was inside the Mizuno USA network between August 21 and October 29, 2024 and copied files periodically over that period. The activity was discovered on November 6, 2024, and the company said its review of the affected files was completed on December 18, 2024.

The information involved differed from person to person and included names, Social Security numbers, driver's licence details, financial account information and passport numbers. Mizuno USA did not state how many people were affected, leaving that field blank in its regulatory filing, and did not respond to press requests for comment.

The BianLian extortion group had claimed the breach on its leak site in November 2024, months before the company confirmed it. The group said it had taken finance and human resources records, contracts and confidential agreements, trade secrets and patents, mailboxes and email correspondence. Mizuno USA offered those notified a year of complimentary credit monitoring and identity protection and advised them to watch their accounts and credit reports for signs of fraud.

Sources