Skip to content

Contractor malware exposes 8.7M Daiichi Kosho karaoke records

Malware at Nippon Columbia Group, a Daiichi Kosho contractor, put about 8.7 million karaoke customer and employee records at risk. No leak confirmed yet.

Published 3 min read

Japanese karaoke operator Daiichi Kosho says a malware infection at one of its data-handling contractors, Nippon Columbia Group (NCG), put roughly 8.7 million customer and employee records at risk. Daiichi Kosho disclosed the incident in a notice on October 8 and an update on October 9, and says it has not confirmed any actual leak or misuse.

What's affected

NCG handled personal data that Daiichi Kosho had outsourced. Per the company's notice, the affected store held about 8,724,000 records: roughly 8,631,000 customer records (after removing about 515,000 duplicates) and roughly 93,000 employee records. The customer total breaks down across Daiichi Kosho's brands:

  • Big Echo — about 5,558,000
  • DK Dining — about 3,462,000
  • CLUB DAM — about 74,000
  • Megabig — about 43,000
  • Banana Club — about 5,000
  • B-GARAGE — about 4,000

Exposed fields are registered name, gender, date of birth, email address, and phone number. Daiichi Kosho says passwords and payment-card data are not in the set, and that loyalty points cannot be used with this information alone.

Exploitation status

The malware hit a single NCG employee PC. NCG detected the infection between October 1 and 2, isolated the machine on October 2, and informed Daiichi Kosho on October 5. No threat actor has claimed the data, and no ransomware component has been reported. Daiichi Kosho says there is no confirmed leak, no observed misuse, and no impact on its own systems; the investigation into cause and scope is ongoing. As of October 11, BleepingComputer reported no sign of the data being posted publicly (BleepingComputer).

What to do today

  1. If you hold a Big Echo, CLUB DAM, or DK Dining account, treat any email, SMS, or call referencing it as suspect — name, date of birth, email, and phone are exactly the fields that make phishing and vishing convincing. Daiichi Kosho says it will never ask for passwords or card details.
  2. The loyalty accounts themselves do not need a reset — credentials were not in the exposed set — but rotate that email's password anywhere you reused it.
  3. If you outsource customer data, confirm in writing the clock your contractors run between detecting an infection and notifying you. NCG's gap — detection October 1–2, client notification October 5 — is the number to benchmark against.
  4. Set leak-forum and paste-site alerts on the affected brand names and your email domains so you catch any publication early.

Context

The record count sits almost entirely in two chains, Big Echo and DK Dining, and none of it lived on systems Daiichi Kosho audits directly — it sat with a contractor. That is the recurring shape of this month's wave of large Japanese disclosures: the breached data concentrates in outsourced marketing and reservation stores, one subcontractor PC away from the brand whose name ends up in the headline. Vendor oversight, not the company's own perimeter, is where the exposure lived.

Related stories