Listen to this Post

In October, Japan’s Askul Corporation, a major player in the office supplies and logistics e-commerce sector, fell victim to a significant ransomware attack by the cybercriminal group RansomHouse. The attack, which caused widespread disruptions, resulted in the theft of sensitive data, including customer records and internal company information. This breach has not only disrupted operations but has also raised questions about cybersecurity practices within large corporations. Here’s a breakdown of the incident and its aftermath.
The Incident: What Happened?
Askul Corporation, owned by Yahoo! Japan, is a major business-to-consumer and business-to-business e-commerce company. The company is known for offering office supplies and logistics services, with clients ranging from individual consumers to large companies like Muji. In October, Askul was struck by a ransomware attack that led to a complete IT system failure. This failure caused disruptions in shipping, including halted deliveries to major retailers like Muji.
The hackers, identified as the RansomHouse group, managed to steal a substantial amount of sensitive customer data during the breach. According to Askul’s report, the compromised data includes:
Business customer service data: Around 590,000 records.
Individual customer service data: Roughly 132,000 records.
Business partner data: Around 15,000 records.
Employee and executive data: Approximately 2,700 records.
As part of their efforts to mitigate the damage, Askul withheld specific details about the compromised data to prevent exploitation. The company has also reported the breach to Japan’s Personal Information Protection Commission and promised to notify affected customers and partners individually.
By December 15, the company had yet to restore its shipping systems fully, with delays still ongoing. The company’s investigation into the extent of the breach confirmed that the ransomware attack involved multiple variants, including those that bypassed updated security measures, such as endpoint detection and response (EDR) software.
RansomHouse’s Methods and Execution
The ransomware group RansomHouse is known for both encrypting systems and stealing sensitive data, with the aim of extorting victims for ransom. In Askul’s case, the cybercriminals gained access through a compromised authentication credential from an outsourced partner’s administrator account that lacked multi-factor authentication (MFA). Once inside the network, the attackers were able to move laterally across multiple servers, gather critical authentication data, and disable security measures.
The ransomware attack itself was not a simple affair: the cybercriminals deployed ransomware payloads across multiple servers and wiped backup files to prevent easy recovery. To mitigate further damage, Askul took immediate action by physically disconnecting the affected networks, isolating compromised devices, and resetting passwords for all administrator accounts. MFA was also enforced across all key systems.
What Undercode Says:
The attack on Askul highlights the growing sophistication of modern cybercriminal groups and their ability to exploit even minor vulnerabilities to cause significant disruption. The fact that RansomHouse was able to breach Askul’s network through a compromised outsourced partner’s account reveals the importance of securing third-party access. While MFA was not initially implemented for all critical accounts, Askul responded swiftly by enhancing security measures after the breach, including implementing MFA across all key systems.
The use of multiple ransomware variants in the attack underscores a worrying trend. Hackers are increasingly using complex, multi-pronged methods that not only disrupt operations but also complicate recovery efforts. By wiping backups and encrypting data across multiple servers, RansomHouse ensured that the restoration process would be prolonged and difficult.
Askul’s decision to disclose the breach and notify affected customers is commendable, but it also reveals a significant gap in cybersecurity preparedness. Although they had some security measures in place, the attack exploited vulnerabilities in the partner network, showing that even large organizations are vulnerable to breaches if their supply chain and partner security protocols are not airtight.
From a broader cybersecurity perspective, this incident is a stark reminder of the risks posed by outsourcing and third-party vendors. Companies like Askul should prioritize not only internal security but also demand stringent security practices from their partners. Additionally, enforcing MFA and using other advanced threat detection tools across all systems is no longer optional but a necessity to safeguard sensitive information.
The delay in restoring normal operations and the lack of a clear financial impact assessment at the time of reporting further emphasize how complex and disruptive these ransomware attacks can be. As the cybersecurity landscape evolves, companies must recognize that a successful breach can have far-reaching consequences beyond just data theft, affecting everything from customer trust to operational efficiency.
Fact Checker Results:
Data Breach Scale: Askul confirmed that around 740,000 customer and partner records were compromised during the attack. This aligns with the extent of the reported breach, which also included employee data and business partner information.
Security Gaps: The hackers exploited a lack of MFA on an outsourced partner’s administrator account, highlighting a vulnerability that companies often overlook—third-party access.
Ongoing Recovery: As of mid-December, Askul was still working to fully restore its shipping systems, demonstrating how deep the impact of such an attack can be on operations.
Prediction:
Given the increasing sophistication of ransomware groups and the widespread vulnerabilities in both internal and third-party systems, it’s likely that we will see more attacks like the one on Askul. The trend of targeting companies via weak third-party access points will likely continue to grow, as hackers take advantage of the interconnectedness of modern supply chains. In the future, businesses will need to adopt a zero-trust security framework, prioritizing the secure management of both internal and external access. Additionally, with ransomware attacks becoming more destructive, we can expect regulatory bodies to impose stricter cybersecurity requirements, especially for companies handling sensitive customer data. The financial impact of such breaches will likely lead to more insurance claims, further pressuring organizations to invest in stronger security measures.
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: www.bleepingcomputer.com
Extra Source Hub (Possible Sources for article):
https://www.reddit.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
Bing
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon



