On October 5, Daiwa Securities disclosed an incident involving servers operated by Scala Communications, a customer communications provider. Unauthorized access reportedly occurred on October 2 and 3. Daiwa estimates that up to 110,000 customers and about 220,000 records may be involved.
The provider at the center
The affected systems belonged to Scala, not Daiwa’s trading systems, according to the company. Accessed information may include contact and account details used for communications. Daiwa’s initial notice did not report access to customers’ login credentials.
What the 220,000 figure means
Daiwa refers to up to 110,000 customers and 220,000 records, which may mean multiple items per customer. The figures should not be read as 220,000 distinct people. The investigation is determining what data was present and actually accessed.
Fraud risk and stated limits
Contact details can make fraudulent messages impersonating Daiwa more convincing. The company says the data alone cannot access brokerage accounts or execute trades, and it had detected no misuse when it announced the incident. Those findings may change as the investigation progresses.
What customers can check
Treat unexpected calls about a portfolio, payment or urgent verification with caution. Do not share a password, MFA code or card information. If in doubt, open the Daiwa app or bookmarked website yourself and contact support through that channel.
How this relates to Soclyde
A password manager cannot fix a third-party provider’s security. Soclyde can help teams avoid spreading shared secrets with a provider across files or hard-to-control conversations. Risk reduction also requires vendor inventories, least-privilege access and prompt incident notification.
Key points
Keep the disclosed scope in view, while distinguishing observed access from confirmed misuse. Follow official updates and apply the steps relevant to your accounts. For team secrets, see our secure password sharing guide or contact Soclyde.



