← Incident database

askul-2025 · Disclosed 2025-10-19

ASKUL: access through an MFA exception

Stolen credentials for a contractor administrator account without MFA enabled a ransomware intrusion.

Credentials

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    A contractor account was misused; the original credential leak remains unresolved.

    [s1]6. 調査結果 (1)
  • Reported fact

    Some servers lacked EDR and continuous monitoring; encrypted or deleted backups impeded recovery.

    [s1]6. 調査結果 (2)–(5)

Timeline

  1. Incident disclosed. [s1]

Reported response

  • Reported fact

    ASKUL reported credential resets, MFA rollout, and environment rebuilding.

    [s1]7. 対応状況

Evidence relevant to prevention

Operational controls to inspect

Inspect MFA exceptions and contractor privileges, plus protected backups and restoration tests.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence.

Credential theft origin is unresolved; the report found no evidence that the VPN vulnerability was exploited.

Sources

  1. [s1] ASKUL · Primary source

    ランサムウェア攻撃に関する調査結果および今後の対応について ↗

    Published 2025-12-12 · Reviewed 2026-10-02