Investigation into the incident launched along with third-party cybersecurity experts after the discovery and takedown of systems impacted by atypical activity revealed the exfiltration of a subset of files.
Threat actors leveraged the flaw to target a toast advertisement program with an unsupported Internet Explorer module, which when installed would trigger a type confusion error and several malicious action.
Iranian hackers have launched password spraying, multi-factor authentication push bombing, and other brute-force attack methods to infiltrate healthcare and public health, information technology, energy, engineering, and government organizations' networks.
Such a development comes months after National Public Data admitted the exposure of a database stolen from a December 2023 breach beginning in April, which was then followed by civil penalties being sought by over 20 states as well as potential fines from the Federal Trade Commission.
Investigation into the incident revealed the exfiltration of personal data from Casio and its affiliates' permanent and temporary employees, business partners, customers, and interviewed prospects for employment, as well as contracts with business partners.
Aside from the names and contact information of 2,606 Game Freak employees and contractors, such data exposure also revealed internal files, concept art, and other development documents from over 25 years ago, including designs from Pokemon Black and White, source patch files for Pokemon Black and White 2, and Pokemon Go test build assets.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.