February 27, 2004

Data theft hits 4.5 MM Softbank accounts

4.5 million subscriber names, phone numbers, postal addresses, email addresses and Yahoo Japan IDs were leaked from Softbank Corp., the largest provider of broadband access in Japan, it reported to Reuters.

Toyko police arrested four individuals suspected of stealing the confidential data and demanding a payment from Softbank to avoid it being leaked. An insider is suspected. Softbank's CEO Masayoshi Son accepted responsibility, apologized and took a 50% salary cut for 6 months. Reuters reported that credit card, bank account and password details on a separate database were not compromised.

Softbank said it has since put restrictions on how many staffers can access databases, and upgraded a system of logging access history.

Source:Yahoo! News - Softbank Says Data on 4.52 Million Subscribers Leaked(2/27/04).

Questions:

  • Are background checks and stronger audit controls necessary for those with access to sensitive databases?
  • If one of the larger companies in Japan has this vulnerability, how many others in the developed world are also at risk?
  • Is this a failure of security best practices, or a failure to *follow* security best practices?

    DougSimpson.com/blog

    Posted by dougsimpson at February 27, 2004 01:51 PM | TrackBack
  • Comments