SOCLYDE logo
Current languageEN
Cybersecurity newsCybersecurityData breachSecurity advisory

Daiwa data exposed through a service provider

An incident at Scala Communications exposed Daiwa customer data; brokerage accounts were not affected, the company says.

By Soclyde Team

An employee files an unmarked document in a financial office

In summary

  • The Scala Communications incident may affect up to 110,000 Daiwa customers and 220,000 records.
  • Daiwa says the exposed data alone cannot access brokerage accounts or execute trades.
  • Beware of messages impersonating Daiwa; contact the company through its official app or website.

Explore next

Soclyde resources

Article contents

On October 5, Daiwa Securities disclosed an incident involving servers operated by Scala Communications, a customer communications provider. Unauthorized access reportedly occurred on October 2 and 3. Daiwa estimates that up to 110,000 customers and about 220,000 records may be involved.

The provider at the center

The affected systems belonged to Scala, not Daiwa’s trading systems, according to the company. Accessed information may include contact and account details used for communications. Daiwa’s initial notice did not report access to customers’ login credentials.

What the 220,000 figure means

Daiwa refers to up to 110,000 customers and 220,000 records, which may mean multiple items per customer. The figures should not be read as 220,000 distinct people. The investigation is determining what data was present and actually accessed.

Fraud risk and stated limits

Contact details can make fraudulent messages impersonating Daiwa more convincing. The company says the data alone cannot access brokerage accounts or execute trades, and it had detected no misuse when it announced the incident. Those findings may change as the investigation progresses.

What customers can check

Treat unexpected calls about a portfolio, payment or urgent verification with caution. Do not share a password, MFA code or card information. If in doubt, open the Daiwa app or bookmarked website yourself and contact support through that channel.

How this relates to Soclyde

A password manager cannot fix a third-party provider’s security. Soclyde can help teams avoid spreading shared secrets with a provider across files or hard-to-control conversations. Risk reduction also requires vendor inventories, least-privilege access and prompt incident notification.

Key points

Keep the disclosed scope in view, while distinguishing observed access from confirmed misuse. Follow official updates and apply the steps relevant to your accounts. For team secrets, see our secure password sharing guide or contact Soclyde.

Frequently asked questions

Were Daiwa accounts compromised?

Daiwa said the incident involved its provider’s servers and that the data alone cannot log in to brokerage accounts or trade.

What data was exposed?

Up to 110,000 customers and about 220,000 records may be involved. The exact data types are still being verified.

How can I avoid a related scam?

Ignore unsolicited requests for codes, passwords or payments. Contact Daiwa using details from its official website.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading