Skip to content

SecurityNot yet confirmed elsewhere1 publisher2 min readPublished

Daiichi Kosho discloses 8.7 million exposed records after malware hit its data contractor

Daiichi Kosho, Japan's largest karaoke maker, says malware at Nippon Columbia, one of its contractors, left more than 8.7 million records on its customers and employees exposed. The data sat with the contractor, so one infected workstation there put 8.6 million karaoke customers in scope.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying Daiichi Kosho discloses 8.7 million exposed records after malware hit its data contractor
Generated illustration
8,631,000 customer records exposed vs 93,000 staff Exposed records split by customers and employees, as disclosed by Daiichi Kosho. They include names, birth dates, emails and phone numbers.

Bar comparison of exposed records: 8,631,000 customer records against 93,000 employee records, according to Daiichi Kosho. Customers make up almost all of the exposure. The records include full names, genders, dates of birth, email addresses and telephone numbers.

Records in the exposed data, per Daiichi Kosho's disclosure In records

8,631,000 customer records exposed vs 93,000 staff (Records in the exposed data, per Daiichi Kosho's disclosure)
ItemValueClaim
Customers8,631,000 records6
Employees93,000 records6

What happened

  • Nippon Columbia Group told Daiichi Kosho on October 5 that it had found malware on an employee's computer, and the affected system was isolated the following day.
  • The exposed records cover 8,631,000 customers and 93,000 employees, with full names, genders, dates of birth, email addresses and phone numbers.
  • Customers of six brands may be affected: Big Echo, Mega Big, Karaoke Club DAM, Banana Club, B-Garage and DK Dining.
  • Daiichi Kosho has not confirmed that any data was stolen or leaked, but it is telling customers to stay cautious.
  • NCG has reset passwords and other credentials and is investigating the cause, the scope and whether any data has been posted online.

Why it matters

  • exposure If the records left NCG's network, 8.6 million karaoke customers can be targeted by scam calls and texts that quote their real birth date and phone number.
  • constraint NCG's credential reset closes the access path on its own side. It does nothing for customers, who cannot change a birth date or a name the way they change a password.
  • decision Operators that hand customer data to a contractor now have to decide how much of the file the contractor's staff computers can reach. Here, by Daiichi Kosho's account, one infected machine led to a disclosure covering 8,724,000 records.

Daiichi Kosho says its own systems were not breached [9]. In our view that changes little for the people in the file. The company outsources the handling of its customers' personal information to Nippon Columbia Group [3]. NCG is an entertainment group. Its businesses are music, video and game software and artist management [3]. The two counts Daiichi Kosho gave add up to 8,724,000 records [15].

The infected system was isolated on October 6 [16]. On the evidence so far this is one infected computer at one contractor [4]. We'd treat it as a single incident until data turns up online or a group claims it. The reporting does not identify the malware, how it reached the employee's machine, who deployed it, or any link to a wider campaign [14].

If the data left NCG's network, an attacker has a customer list with birth dates attached. In our view it does not open accounts on its own. The exposed data does not include passwords, and Daiichi Kosho has seen no evidence of unauthorized use of loyalty points [8]. What the list does allow is a scam call or text that quotes a customer's real name, birth date and phone number to sound official. Daiichi Kosho's advice to customers is to distrust unsolicited email, SMS or phone calls that ask for payment or for personal or financial information [13].

Daiichi Kosho operates 521 karaoke venues across Japan [2] and made the disclosure under its own name [1]. Its Friday update added nothing on whether any data leaked [11]. BleepingComputer could not find a public announcement from NCG about the incident and has asked the firm for a statement [12].

What to watch

  • Whether NCG's investigation finds that data was actually taken, or the records appear on a leak site.
  • A public statement from Nippon Columbia Group on how the malware reached the employee computer and what that machine could access.
  • Reports of scam calls or texts aimed at Big Echo or Karaoke Club DAM customers that quote birth dates or phone numbers.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence45
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence40
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Daiichi Kosho disclosed that a malware infection at its contractor, Nippon Columbia, exposed more than 8.7 million customer and employee records.

    ReportedSupportedSource: Daiichi Kosho disclosure, as reported by BleepingComputerView cited source
  2. [2]

    Daiichi Kosho is the largest karaoke maker in Japan and operates 521 karaoke venues nationwide, including the Big Echo chain.

    ReportedSupportedSource: BleepingComputerView cited source
  3. [3]

    Daiichi Kosho outsources the handling of its customers' personal information to Nippon Columbia Group (NCG), a Japanese entertainment group whose businesses include music, video and game software production and distribution, and artist management.

    ReportedSupportedSource: BleepingComputerView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. bleepingcomputer.com

    1 article · October 11, 2026

    Nippon Columbia malware incident exposes 8.6 million karaoke fan records

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Entities

Loading related stories