← Nippon Columbia Group

2026 Nippon Columbia Group — employee-PC malware; Daiichikosho data ~8.724M at risk

2026 8.7M records affected Share on X

Data compromised

Per Daiichikosho notice naming NCG: ~8.724M Daiichikosho customer/employee records possibly exposed (names, gender, DOB, email, phone). NCG authentication credentials reset; public NCG standalone notice not located at indexing — attestation via controller disclosure.

Technical writeup

Verified via Daiichikosho (data controller) Oct 8, 2026 notice identifying contractor Nippon Columbia Group (NCG). NCG reported malware on an employee PC ~1–2 Oct 2026, isolation on 2 Oct, and possible exposure of temporarily stored Daiichikosho personal data totaling ~8.724M records (field list and brand breakdown in daiichikosho2026). BleepingComputer (11 Oct) notes no standalone public NCG announcement located at press time. companyConfirmed true (controller-attested contractor incident); recordsAffected 8724000 (same census as controller notice).

Root cause

Malware infection on one NCG employee PC (found ~Oct 1–2 2026; isolated Oct 2) holding temporarily stored personal data processed for Daiichikosho

References