Investigation into the incident revealed the exfiltration of personal data from Casio and its affiliates' permanent and temporary employees, business partners, customers, and interviewed prospects for employment, as well as contracts with business partners.
Aside from the names and contact information of 2,606 Game Freak employees and contractors, such data exposure also revealed internal files, concept art, and other development documents from over 25 years ago, including designs from Pokemon Black and White, source patch files for Pokemon Black and White 2, and Pokemon Go test build assets.
While DumpForums claimed to have infiltrated the company's corporate GitLab server, mail server, and software management services, Dr. Web emphasized that the incident had not resulted in any customer data compromise.
Included in the 6.4 GB SQL database were Internet Archive members' email addresses, usernames, Bcrypt-hashed passwords and password change timestamps, as well as other internal details as recent as September 28, when the attack was believed to have taken place.
While the incident was downplayed by Dr. Web to not have prompted the compromise of any user data, DumpForums hackers said that they were able to steal the company's client/user database, as well as other information stored in its GitLab and corporate email servers, as well as their Jenkins, Confluence, Mantis, and RocketChat instances.
Infiltration of CreditRiskMonitor's systems between July 9 and July 17 enabled the theft of employees' and independent contractors' personally identifiable information.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.