Ransomware

Kadokawa / Niconico BlackSuit Ransomware Attack

πŸ“… 2024-06-08 🦠 BlackSuit
Primary Source β†—

Incident Details

On 8 June 2024, BlackSuit (rebrand of Royal ransomware / Conti successor) attacked Japanese media/gaming giant Kadokawa and its Niconico video platform. 254,241 individuals’ data was confirmed leaked. Attackers threatened to release 1.5 TB of data; Kadokawa reportedly paid approximately $3 million ransom. Niconico was offline for nearly two months; Kadokawa’s stock dropped 20%+ following the attack. Publishing operations, e-book distribution, and the Kadokawa Umbrella shop were disrupted.

Technical Details

Initial Attack Vector
Phishing email compromised an employee account, leading to BlackSuit ransomware deployment across Kadokawa corporate infrastructure and Niconico video-sharing platform
Malware Family
BlackSuit

Timeline

  1. 2024-06-08 Breach occurred
  2. 2024-06-14 Publicly disclosed
  3. 2024-07-01 Customers notified