← NEC

2016–2020 NEC — multi-year unauthorized access to defense-business division servers

2016 Unknown records affected Share on X

Data compromised

Defense-business internal files—vendor stated absence of personal identifiers in the exfiltrated set

Technical writeup

NEC Corporation's January 2020 disclosure admitted attackers had roamed its defense-industry business unit network since at least December 2016, with suspicious traffic spotted in 2017 and roughly 27,000 internal files ultimately flagged after decryption work completed in 2018. NEC publicly asserted stolen material did not contain personal data or program-specific military secrets, framing the episode alongside contemporaneous Mitsubishi Electric coverage as a wake-up call for Japanese primes.

Root cause

Long-dwell intrusion against internal servers (media speculation pointed to Chinese APT 'Tick' without NEC confirmation)

References