Major Japanese Publisher Kodansha Hit by Phishing Attack, Over 3,800 Records Leaked
Japanese publisher Kodansha disclosed a phishing attack in July 2026 where an employee was tricked into entering authentication credentials on a fake login page, resulting in the leak of approximately 3,800 contact records. Attackers subsequently used the compromised email account to send phishing messages to over 550 recipients.
Incident Overview
On July 27, 2026, a Kodansha employee clicked on a link in a phishing email impersonating a business partner. After entering authentication credentials on a fake login page, attackers gained access to the email account on July 30. The employee discovered the unauthorized access on the same day and changed the password, preventing further incidents.
Scale of Damage
The leaked information includes:
- Personal Records: Approximately 3,812 email addresses and partial employee names
- Secondary Impact: Phishing emails were sent from the compromised account to over 550 recipients
How Phishing Attacks Work
Typical Attack Flow
- Impersonation of Trusted Source - Emails are sent posing as business partners or known companies
- Creating Urgency - Messages contain phrases like "urgent verification required" to pressure recipients
- Directing to Fake Page - Recipients are redirected to fraudulent login pages that closely mimic legitimate ones
- Credential Theft - Victims unknowingly enter user IDs, passwords, and two-factor authentication codes
- Account Takeover and Escalation - Attackers use stolen credentials to access real accounts and amplify the breach
Warning Signs
Sender Verification
- Check if the email address uses an official corporate domain (@kodansha.co.jp) or a suspicious free email account
- Look for misspelled domain names designed to trick recipients
Email Content Red Flags
- Grammatical errors or unnatural phrasing
- Vague requests for "verification" without specific transaction details
- Inconsistencies in sender name or signature
Link Verification
- Hover over links without clicking to verify the actual destination URL
- Confirm the URL matches the legitimate company domain
Login Page Inspection
- Compare the page appearance with known legitimate login screens
- Verify HTTPS protection (padlock icon in URL bar)
- Watch for unusual additional requests or unexpected information fields
Prevention Tips
Individual Level
- Never click links in suspicious emails - Instead, navigate directly to official websites using browser bookmarks or typing the URL manually
- Enable two-factor authentication (2FA) - This adds a second security layer through authenticator apps or SMS codes
- Change passwords regularly - Update passwords for critical accounts every three months
- Use password managers - Securely store and manage complex, unique passwords
Organizational Level
- Employee security training - Conduct regular awareness programs about phishing threats
- Email security tools - Deploy automated filtering systems to detect and quarantine suspicious emails
- Access control policies - Grant employees only minimum necessary permissions
- Monitoring systems - Implement tools to detect unusual access patterns
Reporting and Support
- Personal Information Protection Commission (Japan): https://www.ppc.go.jp/
- IPA Phishing Countermeasures: https://www.ipa.go.jp/
- Internet Service Providers: Report to your ISP's security department
- Internal Reporting: Contact your organization's IT or security department immediately
Source: Cool3c