3rd Update Regarding Data Security Incident Due to Unauthorized Access By Capcom Team January 15, 2021
On
November 16, 2020 (JST) Capcom announced that it had verified
that the personal information of 9 people had been compromised
in this attack. As an update to its ongoing investigation, the
company has verified that the personal information of an
additional 16,406 people has been compromised, making the
cumulative number since this investigation began 16,415 people.
Further, the company has also ascertained that the potential
maximum number of customers, business partners and other
external parties etc., whose personal information may have been
compromised in the attack is approximately 390,000 people (an
increase of approximately 40,000 people from the previous
report), the details of which are listed in "2. Potentially
compromised data (updated)" below.
Capcom offers its sincerest apologies for any complications and
concerns that this may bring to its potentially impacted
customers as well as to its many stakeholders. As
there is an ongoing investigation in place, it is possible that
new facts may come to light going forward. Below is a general
summary of what new information has been confirmed at this point
in time (as of January 12, 2021). Further, because the overall
number of potentially compromised data cannot specifically be
ascertained due to issues including some logs having been lost
as a result of the attack, Capcom has listed the maximum number
of items it has determined to potentially have been affected at
the present time. 1.
Information verified to have been compromised (updated) 2.
Potentially compromised data (updated)
*Cumulative maximum number of potentially compromised
data for customers,
*Regarding the cumulative maximum number of potentially
compromised data above: as part of its ongoing
investigation, Capcom has determined that it currently
does not see evidence for the possibility of data
compromise for the approximate 18,000 items of personal
information from North America (Capcom Store member
information and esports operations website members) that
the company included in its November 16, 2020
announcement. As such, these have been removed from this
cumulative maximum number of potentially compromised
data. None
of the at-risk data contains credit card information. All online
transactions etc. are handled by a third-party service provider,
and as such Capcom does not maintain any such information
internally.
Additionally, the areas that were impacted in this attack are
unrelated to those systems used when connecting to the internet
to play or purchase the company's games online, which have
continued to utilize either an external third-party server or an
external server. As such, these systems have been unaffected by
this ransomware attack and it is safe for Capcom customers or
others to connect to the internet to play or purchase the
company's games online.
3. Support for
individuals whose personal information or corporate information
has been confirmed to have been compromised and those whose
information has potentially been compromised
i. Action
addressing personal or corporate information confirmed to
have been compromised
ii. Action
addressing potentially compromised personal information 4.
Measures going forward
i. Capcom will
continue coordinating with law enforcement authorities in
Japan and the U.S., and also give timely reports to and
receive advice from the institutions responsible for the
protection of personal information in each country.
ii. The company
is working with parties such as a major IT security
specialist company to work toward understanding the overall
damage caused by the attack and preventing any reoccurrence.
A report will be issued following the close of the
investigation.
iii. Capcom is
continuing to work toward improving its security going
forward, with activities that include holding preparatory
meetings ahead of the launch of its Information Technology
Security Oversight Committee, which will function as an
advisory group on matters related to system security from
external security experts. Two university professors, one
external lawyer and one certified public accountant that is
an IT system audit specialist, all of whom possess extensive
knowledge in the field of security, have agreed to join this
committee.
Capcom would once again like to reiterate its deepest apologies
for any complications or concerns caused by this incident. As a
company that handles digital content, it is regarding this
incident with the utmost seriousness. In order to prevent the
reoccurrence of such an event, it will endeavor to further
strengthen its management structure while pursing legal options
regarding criminal acts such as unauthorized access of its
networks. |
Terms of Use | Copyright © 2002 - 2021 CONSTITUENTWORKS SM CORPORATION. All rights reserved. | Privacy Statement