2016–2020 NEC — multi-year unauthorized access to defense-business division servers
Data compromised
Defense-business internal files—vendor stated absence of personal identifiers in the exfiltrated set
Technical writeup
NEC Corporation's January 2020 disclosure admitted attackers had roamed its defense-industry business unit network since at least December 2016, with suspicious traffic spotted in 2017 and roughly 27,000 internal files ultimately flagged after decryption work completed in 2018. NEC publicly asserted stolen material did not contain personal data or program-specific military secrets, framing the episode alongside contemporaneous Mitsubishi Electric coverage as a wake-up call for Japanese primes.
Root cause
Long-dwell intrusion against internal servers (media speculation pointed to Chinese APT 'Tick' without NEC confirmation)