← Incident database
askul-2025 · Disclosed 2025-10-19
ASKUL: access through an MFA exception
Stolen credentials for a contractor administrator account without MFA enabled a ransomware intrusion.
Credentials
Outcome: Confirmed breach
Entry path and evidence
Timeline
Incident disclosed. [s1]
Reported response
- Reported fact
ASKUL reported credential resets, MFA rollout, and environment rebuilding.
[s1]7. 対応状況
Evidence relevant to prevention
Operational controls to inspect
Inspect MFA exceptions and contractor privileges, plus protected backups and restoration tests.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
AI involvementUnknown
The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence.
Credential theft origin is unresolved; the report found no evidence that the VPN vulnerability was exploited.
Sources
[s1] ASKUL · Primary source
ランサムウェア攻撃に関する調査結果および今後の対応について ↗Published 2025-12-12 · Reviewed 2026-10-02