Skip to content
InYourGeek
visiteur@inyourgeek — shell
↹ compléter↑↓ historique⏎ ouvrirhelp
FR
Security· 3 min read

Daiichi Kosho: 8.7 million records exposed at a third-party provider

Malware found in early October on a Nippon Columbia workstation has exposed more than 8.7 million customer and employee records belonging to Daiichi Kosho. The Japanese karaoke giant was not attacked itself: the data had been entrusted to a service provider.

Empty karaoke booth with a microphone on a table, a screen in the background and a padlock symbol overlaid, illustrating a data exposure at a service provider

Daiichi Kosho, Japan’s leading karaoke manufacturer, has disclosed a security incident at Nippon Columbia Group (NCG), the provider that handles its customers’ personal data on its behalf. According to Bleeping Computer, which reported the announcement on 11 October 2026, more than 8.7 million records are involved. This information comes from a single source, Daiichi Kosho’s own statement as relayed by that outlet, so you should read it with that caveat in mind.

What happened

On 5 October, Nippon Columbia informed Daiichi Kosho that malware had been found on one of its employees’ computers. The affected system was isolated the following day. NCG is a Japanese entertainment group whose activities include music, video and game production and distribution, as well as artist management. Daiichi Kosho had entrusted it with processing its customer data.

Daiichi Kosho states that its own systems were not compromised. For its part, NCG has reset passwords and other authentication credentials, and is investigating the origin and scope of the incident, as well as whether the data may have been published online. At this stage, no theft or leak has been confirmed. An update released on Friday brought no new information on this point. Bleeping Computer says it found no public statement from NCG about the incident and is awaiting a response.

The data involved

The exposed records cover 8,631,000 customers and 93,000 employees. They contain:

  • full names;
  • gender;
  • dates of birth;
  • email addresses;
  • phone numbers.

According to the company, passwords are not included, and there is no indication that loyalty points have been used fraudulently. Potentially affected customers are those of several of the group’s brands: BIG ECHO, MEGA BIG, Karaoke CLUB DAM, Banana Club, B-GARAGE and DK Dining. Daiichi Kosho operates 521 karaoke venues across Japan, including the Big Echo chain, one of the most popular in the country.

What affected people can do

Since no passwords are involved, the main risk is phishing. An email address, a phone number, a name and a date of birth are enough to write a convincing message that appears to come from the brand or from a well-known service. The advice being given is therefore to treat with caution any unexpected request, whether by email, text message or phone call, that asks you for a payment or for personal or banking details. A date of birth cannot be changed: that caution needs to last, not just for the weeks following the announcement.

The risk carried by the provider

This incident highlights something customers often overlook: their data does not always stay with the company they gave it to. Here, the organisation that made the announcement was not the one attacked. The entry point was at a service provider, on a single workstation, and that was enough to put millions of records at risk.

For a company, outsourcing data processing does not outsource the risk. The extent of any exposure depends on what the provider holds, how it segregates that data and how quickly it detects an intrusion. In this case, the intrusion was detected and the system was isolated within a day. The investigation has yet to establish whether the data left the network.

If you sang at a Big Echo venue, you had no way of knowing that your record was held by a music company. You are finding out now, through the incident itself.

Sources (1)

Written with AI assistance from the sources cited above, then reviewed and approved before publication by Sébastien Soulier.