The encyclopedia · Legal & Compliance · Legal decision · 2023–2024
A subcontractor's shared login let attackers leak 440,000 LINE items
Malware on a Korean subcontractor's PC plus a shared login opened LINE Yahoo's internals, and 440,000 items leaked before Japan's regulator stepped in.
LINE Yahoo Corporation · 2023-10-09
What happened
In October 2023 attackers reached LINE Yahoo's internal systems through a subcontractor. Malware on a PC owned by an employee of NAVER Cloud, a Korean subcontractor, combined with an authentication system the two companies shared for personnel data, let unauthorised parties into the former LINE Corporation's systems.
The breach leaked 440,000 items of personal data: 302,569 records on LINE users, 86,105 on business partners and 51,353 on employees and other personnel. No chat messages, bank details or credit-card data were exposed, and the company said the most sensitive systems were not reached.
Because LINE Yahoo operates systems tied to Japan's digital administration, the leak drew national attention. Japan's Personal Information Protection Commission carried out an on-site inspection and in March 2024 issued a recommendation, finding inadequate security management measures and ordering the company to make corrections and file repeated improvement reports. A separate Yahoo Auctions identifier-exposure risk drew a formal guidance notice.
Why it happened
- Sharing authentication credentials with a subcontractor turned one infected PC into a door into the parent's systems — the trust extended farther than the security reached.
- Operating a national digital-service platform with ordinary vendor security turned a routine breach into a matter of public concern and a regulator's priority.
- Outsourcing development without ring-fencing access let the compromise cascade from the vendor across the whole group.
The lesson
Credentials shared with a vendor are credentials an attacker can reach — a breach at a subcontractor becomes a breach at the parent unless access and trust are ring-fenced.
Sources
- Notice of unauthorised access to personal information — LY Corporation
- LINE operator says 440,000 personal data items leaked — The Japan News / Kyodo
- PPC briefing on the LINE Yahoo cases — Personal Information Protection Commission
spotted an error? The club wants to know.
More like this
Recruit scored students' odds of ghosting a job offer, sold the score to employers
HP India rigged government tenders through its resellers — ₹142.37 crore CCI fine
Amazon's €746M GDPR record fine was scrapped on a technicality
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.