Daiichi Kosho, operator of Japan’s largest karaoke venue network including the popular Big Echo chain, has disclosed a data exposure incident stemming from a malware infection at its outsourcing partner, Nippon Columbia Group (NCG). The breach reportedly affects more than 8.7 million records.

Daiichi Kosho runs 521 karaoke venues across Japan and outsources handling of customer personal information to NCG, an entertainment conglomerate involved in music, video and game production, and artist management. NCG notified Daiichi Kosho on October 5 that malware had been discovered on an employee’s computer, and the affected system was isolated the following day.

Scope of exposed data

The exposed dataset reportedly covers roughly 93,000 employees and 8,631,000 customers. The information includes:

  • Full names
  • Genders
  • Dates of birth
  • Email addresses
  • Telephone numbers

Daiichi Kosho says passwords were not part of the exposed data, and there is currently no evidence of unauthorized use of customer loyalty points. The company has not confirmed any actual data theft or public leak, though it is urging affected customers to remain cautious.

Brands affected

The incident may impact customers across several Daiichi Kosho brands, including BIG ECHO, MEGA BIG, Karaoke CLUB DAM, Banana Club, B-GARAGE, and DK Dining.

Daiichi Kosho states that its own systems were not directly breached and that the malware infection occurred solely within NCG’s environment. NCG has since reset passwords and other authentication credentials tied to the affected system and is investigating the root cause and full scope of the compromise, including whether any data has surfaced online.

As of a Friday update, no additional details had been released regarding the possibility of a public data leak. NCG has not issued its own public statement on the incident.

Recommendations for affected individuals

Daiichi Kosho is advising customers and employees to treat unsolicited emails, SMS messages, or phone calls requesting payment or sensitive personal and financial information with suspicion, as exposed contact details could be leveraged for phishing or social engineering attempts.