← Incident database

ryomo-systems-2026 · Disclosed 2026-09-28

両毛システムズ(大東ガス・伊勢崎市): unauthorized access and impact

Ryomo Systems’ internal network was compromised; Daito Gas’s customer system was separated, but old working files remained in the vendor network. About 124,000 Daito Gas records may have been extracted. Attackers reached Ryomo Systems’ file server through a VPN and ransomware was confirmed; the VPN compromise method is undisclosed. 3,789 Isesaki student-account records, including passwords, may have been exposed.

Supply chain / CICause unresolved / undisclosed

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    Ryomo Systems’ internal network was compromised; Daito Gas’s customer system was separated, but old working files remained in the vendor network.

    [s1]§§1-4
  • Reported fact

    About 124,000 Daito Gas records may have been extracted.

    [s1]§§1-4
  • Reported fact

    Attackers reached Ryomo Systems’ file server through a VPN and ransomware was confirmed; the VPN compromise method is undisclosed.

    [s2]§§1,3,5,6
  • Reported fact

    3,789 Isesaki student-account records, including passwords, may have been exposed.

    [s2]§§1,3,5,6

Timeline

  1. Disclosure date established by the reviewed notice. [s1]

  2. Disclosure date established by the reviewed notice. [s2]

Reported response

  • Reported fact

    Affected parties were warned and further fact checking is underway.

    [s1]§§1-4
  • Reported fact

    Affected passwords were changed and schools and guardians notified.

    [s2]§§1,3,5,6

Evidence relevant to prevention

Insufficient evidence

Undisclosed entry or patch timing prevents an avoidability assessment. Inspect privileges, retrieval logs, retention and deployed configuration using the linked rules.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The reviewed disclosures do not establish attacker use of AI.

The VPN product, CVE and credential-acquisition route are undisclosed; August 14 is detection, not a confirmed intrusion start.

The VPN product, CVE and credential-acquisition route are undisclosed; vendor intrusion detection is not a verified intrusion-start date.

Sources

  1. [s1] 両毛システムズ(大東ガス・伊勢崎市) · Primary source

    両毛システムズ(大東ガス・伊勢崎市):事故に関する公表資料 ↗

    Reviewed 2026-10-09

  2. [s2] 両毛システムズ(大東ガス・伊勢崎市) · Primary source

    両毛システムズ(大東ガス・伊勢崎市):事故に関する公表資料 ↗

    Reviewed 2026-10-09