Full Report
Kadokawa, known for manga, anime and video games, appears to have made an extortion payment to cybercriminals, according to Kyodo News.
Analysis Summary
# Incident Report: Kadokawa Ransomware Attack and Alleged Ransom Payment
## Executive Summary
A major Japanese media company, Kadokawa (known for manga, anime, and video games), suffered a significant ransomware attack earlier this year, attributed to the Russia-linked BlackSuit group. The attackers compromised 1.5 TB of data, leading to the temporary shutdown of the Niconico video platform. Evidence suggests the company negotiated the ransom down from \$8.25 million to approximately \$3 million, which appears to have been paid via cryptocurrency in June, although the threat actors subsequently leaked further data.
## Incident Details
- Discovery Date: Ongoing investigation following reports emerging in September, initial attack likely occurred in June.
- Incident Date: Occurred in June (date not specified).
- Affected Organization: Kadokawa Corporation (including subsidiary Dwango, which operates Niconico).
- Sector: Media, Publishing, Gaming, Entertainment.
- Geography: Japan.
## Timeline of Events
### Initial Access
- Date/Time: Occurred in June (specific initial date unknown).
- Vector: Attack targeted Kadokawa servers located in a data center.
- Details: Specific initial access vector (e.g., vulnerability exploit, phishing) not detailed in the source material.
### Lateral Movement
- Details: Attackers accessed and exfiltrated 1.5 TB of data across various systems. Attackers communicated with executives via email referencing the breach.
### Data Exfiltration/Impact
- Details: 1.5 TB of data stolen, including contracts, internal company documents, and personal information on all employees. The subsidiary Niconico temporarily shut down its live-streaming platform and user channels.
### Detection & Response
- Detection: Investigation ensued after reports of a data leak emerged in September. Third-party security firm Unknown Technologies was commissioned to investigate.
- Response Actions: Company engaged in ransom negotiations with BlackSuit. An alleged payment of \$2.98 million was made in cryptocurrency in June. The company announced in November an expected extraordinary loss of 2.3 billion yen (\$15 million) due to the incident's impact.
## Attack Methodology
- Initial Access: Targeting servers located in a data center (specific method unknown).
- Persistence: Implied by the ongoing communication and subsequent data leaks after the alleged payment.
- Privilege Escalation: Not specified.
- Defense Evasion: Not specified, though successful in exfiltrating 1.5 TB of data.
- Credential Access: Not specified.
- Discovery: Not specified, but full system access enabled data collection.
- Lateral Movement: Implied through access to internal documents and employee PII.
- Collection: 1.5 TB of data collected, including contracts and internal documents.
- Exfiltration: Data was exfiltrated prior to/during ransom negotiation.
- Impact: Data breach, operational disruption (Niconico shutdown), financial loss, and potential non-adherence to the ransom agreement by the threat actors.
## Impact Assessment
- Financial: Kadokawa expects to record an extraordinary loss of 2.3 billion yen (approx. \$15 million) for the fiscal year ending March 2025. Ransom payment allegedly \$2.98 million.
- Data Breach: 1.5 TB of data stolen, including contracts, internal company documents, and personal information on all employees.
- Operational: Temporary shutdown of the Niconico video-posting site's live-streaming platform and user channels.
- Reputational: Internal dissatisfaction among staff regarding the company's response (failure to publicly hold a press conference), coinciding with news of a potential acquisition by Sony.
## Indicators of Compromise
- Network indicators: (Not disclosed/Defanged)
- File indicators: (Not disclosed)
- Behavioral indicators: Communication via email by BlackSuit (a Royal ransomware rebrand) to executives; Cryptocurrency transactions linked to an alleged ransom payment.
## Response Actions
- Containment: Implied by the eventual restoration of Niconico services, but specific containment actions (e.g., isolating affected segments) were not detailed.
- Eradication: Not detailed.
- Recovery Actions: Subsidiary Niconico restored services; ongoing investigation into the full scope of the breach.
## Lessons Learned
- Ransom Negotiation Risks: Security researchers noted that negotiating casually is risky as threat actors often do not honor agreements, evidenced by the subsequent leak of data even after an alleged payment.
- Communication Failure: Employees expressed dissatisfaction with the current administration for failing to hold a press conference following the breach that exposed employee personal information.
## Recommendations
- Review and enhance security controls protecting data center servers used by critical subsidiaries.
- Implement stringent protocols regarding sensitive data handling, especially employee PII.
- Develop and practice effective high-level communication procedures for managing high-impact security incidents, including stakeholder and internal employee notifications.
- Re-evaluate policies regarding engaging with or paying ransomware demands, acknowledging the lack of guarantee for data deletion.