← Pan Pacific International Holdings

2025 PPIH / Don Quijote retail group — ransomware via contractor Acreative (Aug); Oct 10 joint PDF cites encrypted customer & payroll partner servers, exfil ‘not confirmed’

2025 Unknown records affected Share on X

Data compromised

Customer names/addresses/phones/payment-account transaction metadata; employee names/departments for partner-payment processing—per notification tables

Technical writeup

PPIH and flagship banners (Don Quijote etc.) disclosed that outsourcer Acreative KK servers handling invoice/voucher workflows—holding customer transaction and employee payroll-partner segments—were encrypted by ransomware after firewall replacement on 25 Aug 2025. The 10 Oct 2025 PDF states no external leak fact yet, low likelihood from early logs, but cannot fully rule out exposure because restoration was incomplete.

Root cause

Ransomware impacting outsourced managed servers following perimeter work (per joint corporate notice)

References