dandm-vpn-ransomware-2026 · Disclosed 2026-06-12
D&M: unauthorized access and impact
An attacker entered through a VPN device and infected the file server with ransomware; the VPN compromise method is undisclosed. 633 fax-order records from approximately two years may have been disclosed; card and bank-account information was not identified.
Outcome: Confirmed breach
Entry path and evidence
- Reported fact
An attacker entered through a VPN device and infected the file server with ransomware; the VPN compromise method is undisclosed.
[s1]pp.1-2 概要 / 原因 / 現在の状況 - Reported fact
633 fax-order records from approximately two years may have been disclosed; card and bank-account information was not identified.
[s1]pp.1-2 概要 / 原因 / 現在の状況
Timeline
Disclosure date established by the reviewed notice. [s1]
Reported response
- Reported fact
The affected file server was isolated and VPN security measures completed.
[s1]pp.1-2 概要 / 原因 / 現在の状況
Evidence relevant to prevention
Insufficient evidence
Undisclosed entry or patch timing prevents an avoidability assessment. Inspect privileges, retrieval logs, retention and deployed configuration using the linked rules.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The reviewed disclosures do not establish attacker use of AI.
The notice does not establish all entry, timing and extraction details; unresolved claims remain unknown.
Sources
[s1] D&M · Primary source
D&M:事故に関する公表資料 ↗Reviewed 2026-10-09