scala-iask-2026 · Disclosed 2026-10-05
Scala i-ask: administrator intrusion affects customers on a shared server
An intruder installed a program after administrator login. This shared incident covers up to five customers, including three separately verified disclosures.
Outcome: Confirmed breach
Entry path and evidence
- Reported fact
Unauthorized administrator login was followed by installation of a program.
[s1]1. 漏えいの経緯 - Reported fact
Potential exposure spans up to five customers and 713,126 non-deduplicated inquiries.
[s1]2. 漏えいした可能性のある情報 - Reported fact
Daiwa reported potential exposure affecting about 110,000 people and about 220,000 inquiries including unidentifiable records.
[s2]p.2 §2 - Reported fact
Citizen reported about 100,000 people; Sompo reported about 60,000 inquiries. Both describe possible exposure.
Timeline
Reported response
Evidence relevant to prevention
Operational controls to inspect
Inspect administrator authentication, cross-environment privileges, and execution restrictions on upload storage.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The reviewed disclosures do not establish attacker use of AI.
The login mechanism and prior MFA coverage are undisclosed. Customer counts must not be added.
Sources
[s1] スカラコミュニケーションズ · Primary source
i-askへの不正アクセスに関する発表 ↗Published 2026-10-06 · Reviewed 2026-10-09
[s2] 大和証券 · Primary source
外部委託先への不正アクセスによるお客様情報の漏洩の可能性について ↗Published 2026-10-05 · Reviewed 2026-10-09
[s3] シチズン時計 · Primary source
委託先への不正アクセスに関する発表 ↗Published 2026-10-06 · Reviewed 2026-10-09
[s4] 損保ジャパン · Primary source
外部委託先への不正アクセスによる情報漏えいの可能性について ↗Published 2026-10-07 · Reviewed 2026-10-09