Key takeaways

  • Scala Communications (スカラコミュニケーションズ), a Tokyo-based provider of customer support software, says attackers broke into the admin site of its FAQ system i-ask overnight on October 2–3, 2026, planted a program on a server, and may have taken customer inquiries stored there for up to five client companies.
  • Up to 713,126 inquiry records may have leaked: names, email addresses, the text of the inquiries, and other details that vary by client.
  • Two clients have disclosed so far: Daiwa Securities (about 110,000 customers, including account numbers) and Citizen Watch (about 100,000 people who used inquiry forms for its Citizen, Bulova and Frederique Constant brands). The other clients have not been named.
  • Scala detected the attack through a database monitoring alert and cut it off within about 12 hours. Its own list of fixes includes multi-factor authentication for administrators and separating client environments.

What happened#

According to Scala Communications and its listed parent company, Scala, Inc.:

Date and time (2026) Event
Oct 2, about 20:30 A third party logs in to the i-ask admin site without authorization and installs a malicious program on a server Scala manages
Overnight The attacker may have taken inquiry data from the databases of client companies running on the same server
Oct 3, morning A database monitoring alert triggers an investigation. Access is cut off at about 08:00. Affected clients are told the same day
Oct 5 Daiwa Securities discloses
Oct 6 Scala Communications, Scala, Inc. and Citizen Watch disclose

Scala says it has changed the password of the account used, blocked the attackers' IP addresses, quarantined the program, changed administrator passwords in all environments, and changed settings so that uploaded files can no longer be run as programs. It has reported the breach to the Personal Information Protection Commission and consulted the police, and is working with an outside forensic firm.

Scala, Inc. says it will not name the client companies. Daiwa Securities and Citizen Watch disclosed on their own.

Who is affected#

Client People Data that may have leaked
Daiwa Securities About 110,000 customers. About 220,000 items including inquiries without identifying data Name, email address, securities account number, inquiry content
Citizen Watch About 100,000 Name, address, phone number, email address. Bank or card details if customers wrote them into the inquiry field
Up to three other clients Not disclosed Not disclosed
Total Being deduplicated Up to 713,126 inquiry records

Daiwa Securities says the leaked data cannot be used to log in to accounts or trade, and that it has seen no fraudulent trades. It has contacted affected customers individually.

Citizen Watch says the data came from inquiry forms on the websites it runs for its Citizen, Bulova and Frederique Constant brands. It has not said which countries' sites were included. Its online stores, membership services, production systems and internal network were not accessed.

What we don't know yet#

Scala has not said:

  • How the attacker obtained the login for the i-ask admin site
  • Whether that admin account was protected by multi-factor authentication
  • Which other companies are affected. Scala says there were up to five
  • How many people, rather than inquiry records, are affected
  • Whether the program planted on the server was used for anything else

Our analysis#

One login, five companies#

The attacker did not break into Daiwa Securities or Citizen Watch. They logged in to a vendor's admin site, and from one server reached the stored inquiries of several client companies at once. That is the core risk of shared software services: a single weakness at the vendor becomes a breach at every customer that shares the infrastructure.

Scala's own remedy list is telling. It plans to introduce multi-factor authentication for administrators, separate the environments of different clients, strengthen monitoring, and commission regular third-party vulnerability assessments. It has not said what was in place before. But a plan to add MFA and separation after the fact suggests they were not fully in place when the attacker logged in.

Inquiries are more sensitive than they look#

An inquiry form looks harmless. But the free text customers type into it can contain anything. Citizen warns that bank or card details may have leaked if customers wrote them in. For Daiwa, the records combine names, email addresses, securities account numbers and what customers were asking about. That is exactly the material for convincing scam emails: "Regarding your inquiry about your account...". Securities phishing is already a major problem in Japan: IPA's white paper records about ¥740 billion in fraudulent trades after phishing of brokerage accounts in 2025.

Data on a system that was being retired#

Citizen says it had already moved new inquiries to a different system, and planned to stop using i-ask in mid-October, after which all stored personal data would be deleted. The attack came about two weeks before that. Data on about 100,000 people was still on a system the company was leaving. It is the same retention question raised by Osaka Metropolitan University and Dai-ichi Life: data that is no longer needed is still at risk until it is gone.

Vendor management, on paper and in practice#

Daiwa says it selected and managed Scala under its own vendor rules, and is now reviewing all of its existing vendors. Scala Communications lists ISMS (ISO/IEC 27001) certification on its company profile. It has not said whether i-ask is within the certification's scope.

None of this shows that the rules or the certification were inadequate. But it illustrates the point we made about Japan's new supply chain security rating: a vendor can pass checklists and hold certifications while a specific control, such as MFA on an internet-facing admin site, is missing. What protects customers is the control, not the certificate.

Fast detection, at least#

One thing worked. A database monitoring alert caught the attack, and Scala cut it off within about 12 hours, overnight on a Friday into Saturday. Compare that with Rakuten Drive, where access through a stolen administrator account went on for almost eight months.

What this means for readers#

  • If you sent an inquiry to Daiwa Securities online, expect emails or calls that mention your inquiry or account number. Daiwa says the data cannot be used to log in, but do not give anyone your login ID, password, PIN or one-time password. Call Daiwa's dedicated line (0120-851850) if unsure.
  • If you contacted Citizen, Bulova or Frederique Constant through a website inquiry form, watch for messages from Citizen about whether you are affected. If you wrote bank or card details in the message, contact your bank or card company.
  • If your company uses i-ask, ask Scala directly whether your environment was on the affected server, even if you have not been contacted.
  • If you buy software as a service, ask your vendors whether admin access requires MFA and whether your data is separated from other customers'. Those were the two gaps in this case.

Japanese terms at a glance#

Japanese Reading Meaning
スカラコミュニケーションズ Sukara Komyunikēshonzu Scala Communications, Inc.
FAQシステム efu-ē-kyū shisutemu FAQ (help center) system
管理サイト kanri saito Admin site
不正なプログラムを設置 fusei na puroguramu o setchi Installed a malicious program
利用企業 riyō kigyō Client company (user of the service)
名寄せ nayose Deduplicating records by person
委託先管理 itakusaki kanri Vendor (outsourcing) management

We will update this article as other affected companies disclose, and when Scala publishes the results of its investigation.