From our other sites
The story
On October 2, Dai-ichi Life Group and Dai-ichi Life Insurance announced that the HR system jointly used by both companies had suffered unauthorized access, potentially leaking information on roughly 120,000 employees. Of these, about 70,000 belong to former employees. On 5ch, posters lined this incident up alongside the recent string of corporate data breaches — Times Car, Yamato Transport, Seicomart, and others — with many asking “isn’t that too many?” The thread spiraled into speculation about a shared underlying cause and debate over whether AI is being used to carry out these cyberattacks.
Oct 2 (Fri), 16:52 JST
ITmedia NEWS
Dai-ichi Life Group and Dai-ichi Life Insurance announced on October 2 that the HR system used by both companies had suffered unauthorized access, potentially leaking information on approximately 120,000 employees. Of that total, around 70,000 are said to be former employees.
Source: news.yahoo.co.jp / Original article here
What people said
There's no way we can match overseas hackers.
More like AI is going to outclass them even further.
Re: #9
Hackers are using AI.
Apparently there's know-how out there for smooth-talking Claude into getting 'brainwashed' and using it for cyberattacks.
Dai-ichi Life
Yamato Transport
Seicomart
Avahouse
Isn't that getting to be a few too many?
Their systems are old and keep getting breached.
Online banks are more nimble, so they're still safer for now.
Just try working in the IT/web industry once, seriously.
Everyone's awareness of outside intrusion is way too low across the board.
Though some of it's inside jobs too.
Maybe it also fits because of all the flooding this year — water "leaking" (漏れる) everywhere too.
Maybe someone told an AI 'look into Dai-ichi Life' and it went off and did its own digging behind the scenes.
Isn't anyone putting out a statement? All the big names are getting wiped out.
Could they all be running the same database?
Like, is it Oracle or MySQL?
Banks going back to handwritten forms and greeting letters by mail.
It's the servers holding that data that are being targeted.
Even the Digital Agency is trying to ride this wave lol
Apparently they're already discussing building new security systems.
With AI and next-gen PCs — can't quite put it into words, but some seriously powerful stuff has shown up —
so companies are reportedly getting together to hash out new security setups.
They just keep coming.
Even the Digital Agency, before Times…
Why do they even leave settings that allow access from outside the company?
Probably the effect of remote work spreading?
Also because they leave it set up so you can log in and make entries anytime after a transaction.
Can it really leak this easily?
Yeah, it's doable.
You just plant it in advance and trigger it.
Cyberattacks are easy to escalate in a controlled way —
once you've gotten this far, you decide which industry to hit next.
There was a Japanese hacker arrested on suspicion of pranking a bunch of people by force-canceling their accounts,
and it was said AI was used for that too.
As for buzzword of the year, I don't care if it's baseball, the Asian Games,
Jungrilla, or whatever.
If AI had to be one kanji, it's gotta be "愛" (ai, meaning 'love') — same pronunciation, case closed.
It's not like AI suddenly made brute-forcing way faster or anything —
unless the access keys are literally identical across all of them, there's no explaining this many breaches happening at once.
There's definitely a common thread.
The targeted industries do show a pattern, so it seems like something's being narrowed down somehow.
There was that story about companies that contracted the same security firm and granted it full OS-level access —
turned out to be a design flaw in the security software's settings, and once it pushed an update, outages hit everywhere, causing massive damage.
Apple, though, apparently caught on early and refused that level of access on macOS, so it kept running without a hitch.
Come on.
Didn't you know AI is said to recommend working around the Personal Information Protection Act?
Yeah, that's how it looks from the outside.
On the other hand, on the server side itself, how much can actually be logged — like which account accessed what, and how much of that can be retained?
Is the overhead too huge? Is there really no mechanism that keeps all of that?
I'd think things like downloads or copies to disk would at least leave a record.
Ah, thanks for the answer.
I don't know system operations that well, but I guess how much forensic data survives depends on the settings and environment built in beforehand?
Sorry, I don't get what you're saying lol
My bad — correction: not "that well," more like "not at all."
Background and Key Points of This Story
In recent years, a string of data breaches has hit companies and government bodies one after another — Times Car, Yamato Transport, Seicomart, the Digital Agency — and Dai-ichi Life’s announcement lands squarely in that same wave. The thread zeroed in on how “simultaneous” these incidents seem, speculating that a shared security vendor or database might be behind it, but no technical link between the companies has actually been confirmed — this remains pure community speculation. Plenty of posts also suggested AI is being used in these cyberattacks, but cyberattacks themselves have actually been on the rise since before 2022, and no evidence has been presented that directly ties the spread of generative AI to the increase in attack numbers. One point readers can easily miss is that of the 120,000 people affected, 70,000 were former employees whose personal data was still being retained after they left — this wasn’t limited to current staff, a detail that’s easy to overlook in the original report.
*This article is excerpted and summarized from the 5ch (News Express+) thread “Dai-ichi Life Hit by Unauthorized Access — Data on 120,000 Employees Possibly Leaked, Former Staff Included“.
Leave a Reply