Karaoke firm says malware exposed 8.6 million customer records
Daiichi Kosho says Nippon Columbia malware may have exposed personal data for up to 8.7 million customers and employees, though passwords were not affected.
A malware incident at Nippon Columbia Group exposed up to 8.6 million customer records and about 93,000 employees.
Daiichi Kosho outsourced personal data handling to Nippon Columbia Group and says its own systems were not breached.
Exposed data includes full names, genders, dates of birth, email addresses, and telephone numbers, but not passwords.
The company warns customers to be cautious of suspicious emails, texts, or calls requesting sensitive information.
Quick read · 1 min
A malware incident at Nippon Columbia Group, tied to a Daiichi Kosho contractor, could expose about 8.6 million customer records and 93,000 employees. The data include names, birth dates, genders, emails and phone numbers, but not passwords. No confirmed data leaks online yet, and Daiichi Kosho says its own systems were not breached.
What this means for you: if you’ve used these brands, you may see more scam attempts using your contact details. Change passwords where applicable and enable two‑step verification on important accounts.
What’s next: investigators will keep digging. Expect updates from the firms if the situation changes.
Watch for suspicious messages
Protect accounts with 2FA
Monitor account activity
The complex data breach affecting Nippon Columbia Group, a key contractor for the Japanese entertainment giant Daiichi Kosho, could affect up to 8.6 million karaoke fans and more than 93,000 employees. The firms say the malware was found on an employee’s computer and isolated shortly after discovery, with Daiichi Kosho stressing that its own systems were not breached.
In practical terms, this means names, birth dates, genders, email addresses and phone numbers could have been exposed. The companies emphasize that passwords were not part of what was accessed. However, the mix of personal details can still be used in phishing attempts or social engineering, so customers should stay vigilant about unsolicited messages asking for money or credentials.
At issue is how personal information moves through the hands of contractors. Nippon Columbia Group handles a broad slate of music and video distribution, artist management and related services. Daiichi Kosho outsources personal data handling to NCG, which may widen the scope of who could be impacted beyond Daiichi Kosho’s own direct customers.
The firms say they do not yet know whether any data has appeared online or been leaked, and they are continuing investigations. They’ve urged people to monitor accounts for unusual activity and to reset passwords where applicable, especially for services tied to the exposed contact details.
01
What happened and who’s involved
The malware was detected on an employee’s computer at Nippon Columbia Group, a major player in Japan’s entertainment ecosystem, including karaoke venues and software distribution. The breach involved customer and employee records, with the number of affected customers estimated at about 8.6 million and employees around 93,000. Daiichi Kosho says its own systems were not breached and that NCG has reset passwords and authentication details where needed as part of the incident response.
02
What data may have been exposed
From the information disclosed, the exposed fields include full names, genders, dates of birth, email addresses and telephone numbers. No passwords were reported as exposed, and there’s no current evidence that loyalty points were misused. The mixture of personal details can be used to target phishing attempts, so it’s important to treat contact from unknown parties with extra caution.
03
Why this matters to you
For karaoke fans in Japan or anyone who interacted with these brands, the breach underscores how third-party vendors and contractors can create extra risk. If your contact details were shared with Nippon Columbia Group, you might see more convincing scam messages or targeted calls in the months ahead. In practice, the risk is not a direct financial breach at your bank, but it’s enough to justify a cautious approach to online communications and a tighter eye on accounts that use the same email or phone number.
04
What to do now
– Watch for suspicious emails, texts or calls asking for money or sensitive information. Treat unexpected messages with skepticism and verify through known channels.
– If you haven’t already, enable two‑factor authentication on important accounts and consider changing passwords for services tied to the exposed email or phone number.
– Monitor your accounts for unusual activity. If you spot anything unfamiliar, report it to your service provider and consider placing fraud alerts with credit bureaus where applicable.
– Stay informed: the companies say they are continuing investigations. Expect updates as new details emerge.
Daiichi Kosho and Nippon Columbia Group say they are reviewing security practices and cooperating with investigators. If data appears online or if the scope widens, they will likely provide additional notices to customers and employees. For now, the safest move is heightened awareness and routine security habits across any service that uses your personal contact details.
06
Quick answers
Was any password stolen?
No passwords were reported as exposed in the breach, according to the firms involved.
Should I contact the brands directly?
If you’ve interacted with the Big Echo or other Nippon Columbia Group services and you notice odd activity, contact the brand’s official support channels through their verified websites or apps.
Is my data safe if I live outside Japan?
The breach involves Nippon Columbia Group’s operations in Japan. If you provided data to related services or used the brands’ platforms in other countries, take the usual precautionary steps for phishing and credential protection.
A Canadian software engineer built a camera that tracks police vehicles using license plate data, drawing attention from local police and reigniting privacy debates around automatic license plate readers.
Researchers say attackers used a four-word GitHub poem to steer compromised AI hosts to changing command centers, revealing a new way to monetize breached infrastructure.
3 min read
We use cookies to understand how readers use Talk With Tech, so we can make it better. Is that OK? Privacy policy
The Daily Brief
Today's biggest tech stories, in 5 minutes
Every morning, the news that matters from AI, phones, apps and the people shaping tech. Explained in plain English. Free.
One email a day. No spam, unsubscribe anytime. Privacy policy