← Incident database

scala-iask-2026 · Disclosed 2026-10-05

Scala i-ask: administrator intrusion affects customers on a shared server

An intruder installed a program after administrator login. This shared incident covers up to five customers, including three separately verified disclosures.

CredentialsSupply chain / CI

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    Unauthorized administrator login was followed by installation of a program.

    [s1]1. 漏えいの経緯
  • Reported fact

    Potential exposure spans up to five customers and 713,126 non-deduplicated inquiries.

    [s1]2. 漏えいした可能性のある情報
  • Reported fact

    Daiwa reported potential exposure affecting about 110,000 people and about 220,000 inquiries including unidentifiable records.

    [s2]p.2 §2
  • Reported fact

    Citizen reported about 100,000 people; Sompo reported about 60,000 inquiries. Both describe possible exposure.

    [s3][s4]シチズン §漏えいの可能性がある情報 / 損保ジャパン §2

Timeline

  1. Reported start of unauthorized administrator login. [s1]

  2. Monitoring alerted staff; access was blocked. [s1]

  3. Daiwa disclosed its affected information. [s2]

  4. Scala and Citizen published notices. [s1] [s3]

  5. Sompo published its notice. [s4]

Reported response

  • Reported fact

    Scala changed administrator passwords, isolated the program, and restricted execution of uploaded files.

    [s1]3. 現在の対応状況
  • Reported fact

    Stronger authentication, environment separation, and monitoring are planned.

    [s1]3. 現在の対応状況

Evidence relevant to prevention

Operational controls to inspect

Inspect administrator authentication, cross-environment privileges, and execution restrictions on upload storage.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The reviewed disclosures do not establish attacker use of AI.

The login mechanism and prior MFA coverage are undisclosed. Customer counts must not be added.

Sources

  1. [s1] スカラコミュニケーションズ · Primary source

    i-askへの不正アクセスに関する発表 ↗

    Published 2026-10-06 · Reviewed 2026-10-09

  2. [s2] 大和証券 · Primary source

    外部委託先への不正アクセスによるお客様情報の漏洩の可能性について ↗

    Published 2026-10-05 · Reviewed 2026-10-09

  3. [s3] シチズン時計 · Primary source

    委託先への不正アクセスに関する発表 ↗

    Published 2026-10-06 · Reviewed 2026-10-09

  4. [s4] 損保ジャパン · Primary source

    外部委託先への不正アクセスによる情報漏えいの可能性について ↗

    Published 2026-10-07 · Reviewed 2026-10-09