Back to the archive

The encyclopedia · Legal & Compliance · Legal decision · 2023–2024

A subcontractor's shared login let attackers leak 440,000 LINE items

Malware on a Korean subcontractor's PC plus a shared login opened LINE Yahoo's internals, and 440,000 items leaked before Japan's regulator stepped in.

LINE Yahoo Corporation · 2023-10-09

What happened

In October 2023 attackers reached LINE Yahoo's internal systems through a subcontractor. Malware on a PC owned by an employee of NAVER Cloud, a Korean subcontractor, combined with an authentication system the two companies shared for personnel data, let unauthorised parties into the former LINE Corporation's systems.

The breach leaked 440,000 items of personal data: 302,569 records on LINE users, 86,105 on business partners and 51,353 on employees and other personnel. No chat messages, bank details or credit-card data were exposed, and the company said the most sensitive systems were not reached.

Because LINE Yahoo operates systems tied to Japan's digital administration, the leak drew national attention. Japan's Personal Information Protection Commission carried out an on-site inspection and in March 2024 issued a recommendation, finding inadequate security management measures and ordering the company to make corrections and file repeated improvement reports. A separate Yahoo Auctions identifier-exposure risk drew a formal guidance notice.

Why it happened

  • Sharing authentication credentials with a subcontractor turned one infected PC into a door into the parent's systems — the trust extended farther than the security reached.
  • Operating a national digital-service platform with ordinary vendor security turned a routine breach into a matter of public concern and a regulator's priority.
  • Outsourcing development without ring-fencing access let the compromise cascade from the vendor across the whole group.
What it cost440,000 items of personal data leakedcostly

The lesson

Credentials shared with a vendor are credentials an attacker can reach — a breach at a subcontractor becomes a breach at the parent unless access and trust are ring-fenced.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →