Sanrio Entertainment ransomware attack put up to 2 million records at risk
- Organization
- Sanrio Entertainment
- Exploit
- Ransomware
- Industry
- Entertainment
Sanrio Entertainment, the Sanrio subsidiary that runs the Sanrio Puroland indoor theme park in Tama, Tokyo and Harmony Land in Oita Prefecture, disclosed on February 7, 2025 that its systems had been hit by ransomware and that personal information may have been leaked.
The company said the unauthorised access was identified on January 21, 2025, when a network fault took the Puroland Club passport website offline. The site initially carried a notice attributing the outage to network trouble. A subsequent investigation established that ransomware had been deployed and that data had been exposed.
Sanrio Entertainment put the volume of records potentially involved at up to about 2 million. Security NEXT reported that the categories included annual passport holders' names, gender, dates of birth, addresses, telephone numbers and email addresses, records for former Puroland fan club members, Sanrio+ identifiers for some individuals, and information on business partners and current and former employees, including Japanese My Number national identification numbers. Credit card information was not among the data reported as affected.
The company apologised and said it would strengthen its security. It indicated the intrusion was confined to Sanrio Entertainment's own systems rather than the wider Sanrio group. No ransomware group had publicly claimed the attack as of the reporting date, and affected online services remained offline while recovery work continued.