Key takeaways

  • Dai-ichi Life Group (第一ライフグループ) and its core company Dai-ichi Life Insurance (第一生命), one of Japan's largest life insurers, said on October 2, 2026 that attackers broke into the HR system the two companies share.
  • Data on about 120,000 people may have been viewed and taken: about 50,000 current employees and about 70,000 former employees.
  • Records of former office staff go back to 1967: anyone who left since then is included, so some worked at the company nearly 60 years ago. The data covers names, addresses, phone numbers, employee numbers, positions, roles and the names of their managers.
  • The companies say customer data has not been accessed, as far as they have found.

What happened#

According to the companies' notice, they detected unauthorized access to the HR system on September 24, 2026, and confirmed that personal data stored in it may have been viewed and leaked. They published the notice on October 2, addressed to former employees.

Date (2026) Event
Sep 24 Unauthorized access to the employee HR system detected
Oct 2 Notice published: data on about 120,000 current and former employees may have leaked

The only cause given is "unauthorized access by a third party".

Who and what may be affected#

Group Approx. number
Current employees: office staff 13,000
Current employees: sales staff 37,000
Former employees 70,000
Total 120,000

Former employees are included if they were office staff who left in 1967 or later, or sales staff who left in 2017 or later. People seconded to group companies such as Dai-ichi Frontier Life and Dai-ichi Neo Life, and people seconded into the group, are also included.

Data that may have leaked: employee number, name, address, phone number, gender, department, position, role, and the name of their managerial supervisor.

What we don't know yet#

The companies have not said:

  • How the attackers got in, and whether the HR system is run in-house or by an outside provider
  • When the access began, and whether data was actually taken
  • Whether this is a ransomware or extortion case. As of October 3, we have not seen Dai-ichi Life on ransomware leak sites tracked by ransomware.live
  • Whether they have reported to the police or the Personal Information Protection Commission. The notice does not mention either
  • Why the HR system still held data on people who worked at the company nearly 60 years ago

Our analysis#

An HR system that remembers 1967#

The most striking detail is the date range. The HR system held names, addresses and phone numbers of former office staff going back to 1967. Companies do have reasons to keep some records of former employees, such as pensions and employment certificates. But the notice gives no reason, and it is hard to see why everyday HR operations would need contact details of people who worked at the company nearly six decades ago in the same system as current staff.

It is the second time in a week that retention has turned a breach into a bigger one. Times Car kept license images of former members for seven years "to prevent impersonation". In both cases, most of the people affected no longer had any relationship with the company.

An org chart for scammers#

The data is not just a list of names. It includes each person's department, position, role and manager. Together, that is an organization chart of one of Japan's largest insurers. It is exactly what an attacker needs for targeted phishing or business email compromise: a message that appears to come from the right manager, about the right department, to the right person.

About 37,000 of the current employees are sales staff, who deal directly with customers. A scammer who knows a real salesperson's name and branch can more easily pose as them, or as their manager, when contacting customers. Customer data is not affected, according to the companies. But customers may still be the target.

A notice that is hard to verify#

The notice asks former employees to make contact first through a Microsoft Forms link, and otherwise to call two mobile numbers for the HR department. Both may be genuine and practical. But a breach notice that sends people to a generic form and mobile numbers is harder to tell apart from the fake messages that typically follow a breach. Contact details on the company's own domain, or a landline listed elsewhere on its website, would be easier to trust.

Two group companies in three days#

Dai-ichi Life Group has owned Benefit One, the employee benefits provider, outright since 2024. Benefit One disclosed its own, unrelated data exposure on September 30: a known bug that exposed employee data of its clients. The two incidents are different in kind, and neither company has suggested any connection. But they mean the group disclosed two separate incidents involving employee data within three days.

What this means for readers#

  • If you work or have worked at Dai-ichi Life or Dai-ichi Life Group, including office staff who left in 1967 or later and sales staff who left in 2017 or later, assume your name, address and phone number may be included. Be wary of calls, letters and unexpected bills.
  • If you are a Dai-ichi Life customer, customer data is not affected according to the companies. But be careful with contacts that name a real salesperson or manager and ask for personal or payment details. Confirm through a number you already know.
  • If you run an HR system, check how long it keeps former employees' contact details, and whether they need to be in the same system as current staff.

Japanese terms at a glance#

Japanese Reading Meaning
第一ライフグループ Dai-ichi Raifu Gurūpu Dai-ichi Life Group, Inc., the holding company
第一生命保険 Dai-ichi Seimei Hoken Dai-ichi Life Insurance Co., Ltd.
人事システム jinji shisutemu HR system
退職者 taishokusha Former employees
内勤職員 / 営業職員 naikin shokuin / eigyō shokuin Office staff / sales staff
出向者 shukkōsha Employees seconded to another company

We will update this article if the companies publish more.