Daiwa Securities (TYO:8601) said unauthorized access to servers at its outsourcing vendor, Scalara Communications, may have exposed customer information handled through the vendor's internet inquiry management services.
The breach occurred between the evening of Oct. 2 and the morning of Oct. 3, potentially affecting 110,000 customers' personal details and account numbers, or about 220,000 inquiry records in total.
Scalara has implemented emergency security measures, and no further unauthorized access or leakage has been detected, while Daiwa said its own systems remain unaffected. Daiwa plans to notify affected customers individually and said the exposed data cannot be used to access securities accounts or execute transactions.
The firm is reviewing its vendor management practices and will announce further findings and countermeasures as the investigation proceeds, the statement said.