Contractor malware puts 8.7 million Daiichi Kosho records at risk
EditorialBy TrustList Editorial
The Big Echo operator says the data sat on one Nippon Columbia Group employee PC. No leak or misuse is confirmed, and it is reviewing how it oversees contractors.
- Japan
- Tokyo, Japan
- Cybersecurity
- Data Privacy Law
- +1 more
About Contractor malware puts 8.7 million Daiichi Kosho records at risk
Contractor malware puts 8.7 million Daiichi Kosho records at risk
8 October 2026: Daiichi Kosho, which runs Japan's Big Echo karaoke chain, says about 8,724,000 records of customers and staff may have leaked after malware infected a PC at Nippon Columbia Group (NCG), the contractor it pays to handle customer personal data. The exposed fields are names, gender, dates of birth, email addresses and phone numbers. The company says neither an actual leak nor any misuse has been confirmed, and its own systems were not affected.
Not yet independently verified. Nippon Columbia Group has published no statement that we could find, so the account of the infection comes only from Daiichi Kosho's notice. BleepingComputer dates the discovery to 5 October and the isolation to 6 October; Daiichi Kosho's notice says the infection was found on 1 and 2 October and the PC was isolated on 2 October. We will update this when it can be confirmed, and remove this note.
How the data ended up on one PC
According to Daiichi Kosho's notice of 8 October, NCG found malware on one employee's computer between 1 and 2 October and took it off the network on 2 October. After looking into the scope, NCG reported to Daiichi Kosho on 5 October. Personal data from the work Daiichi Kosho had outsourced was being kept temporarily on that machine, which is why the company cannot rule out a leak.
NCG has reset passwords and other credentials and is investigating the cause, the extent of the damage and whether anything was taken, Daiichi Kosho says. Outside specialists are involved.
Which customers are in the count
The notice breaks the figure down by business, for people who registered as members or made bookings:
- Big Echo: about 5,558,000
- DK Dining: about 3,462,000
- Karaoke CLUB DAM: about 74,000
- Mega Big: about 43,000
- Banana Club: about 5,000
- B-GARAGE: about 4,000
- Duplicates removed: about 515,000
- Customer total: about 8,631,000, plus about 93,000 employee records
Passwords are not in the data, and the company says the fields alone cannot be used to spend loyalty points; no point fraud has been seen. It warns customers about phishing emails, text messages and calls, and says it never asks for passwords or card details. A free-dial enquiry line opened on 9 October.
The contractor oversight question
The breach did not touch Daiichi Kosho's systems at all. It happened because millions of customer records were copied to a single workstation at a service provider, outside the controls of the company that collected them. Daiichi Kosho says it will check NCG's findings and its prevention measures with the outside investigators, review how it manages contractors and strengthen that where needed, and inspect the systems it uses as a precaution.
For any business that hands customer data to an outsourcer, the questions this raises are specific: whether the contract allows personal data to sit on end-user machines at all, how quickly the provider must report an infection, and whether the provider's own security tooling is in scope of the client's audits. Here, three days passed between isolation and the report to the client, by the client's own account.
Our vendor management software category lists 13 products and our integrated risk management software category lists ten.
What comes next
Daiichi Kosho says it will publish the affected customer groups and its response if the investigation finds more. Nippon Columbia's own website carried no statement about the incident when we checked on 11 October.
Sources
- Daiichi Kosho: 委託先における個人情報漏えいのおそれについて (possible leak of personal information at a contractor), 8 October 2026
- Daiichi Kosho: notice opening a free-dial enquiry line for the incident, 9 October 2026
- BleepingComputer: Nippon Columbia malware incident exposes 8.6 million karaoke fan records, 11 October 2026
Categories & features
- Japan
- Tokyo, Japan
- Cybersecurity
- Data Privacy Law
- Outsourcing
TrustList Weekly
The week in software and IT, in one email
The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More JapanThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.