top of page

Latest Articles

[Cyber Threat Analysis, Week 5, July 2026] The Importance of "Attack Surface Management" as Seen from Four Major Incidents

  • 14 hours ago
  • 7 min read


■ This Week's Overview: Multiple Cyber Threats Affecting Multiple Companies


In late July, four serious incidents targeting Japanese companies were reported. The attack methods are becoming more diverse and complex, ranging from system failures due to unauthorized access to data breaches via subcontractors. Of particular note is the trend of attacks targeting not just individual companies, but entire supply chains. This week's incidents highlight the importance of not only "vertical defense" but also "horizontal monitoring."



1. Unauthorized access to Wasabi Co., Ltd.: System breach caused by Docker configuration and router malfunction.

In early July 2026, Wasabi Inc. announced that it had experienced unauthorized access to its development environment terminal. In this case, the cause was that the database port of a Docker container was exposed to the outside world, and port forwarding was enabled due to a malfunction in the settings and firmware of the home router, making it accessible from the internet. This is an example of a breach that resulted not from a single vulnerability, but from a combination of multiple configuration problems.


Details of the damage

  • Unauthorized access to development environment terminals

  • Data theft and deletion from a test database

  • Leakage of some API keys and application IDs

  • No leakage of personal information of actual customers has been confirmed.


Response status

  • The system was isolated and initial response measures were implemented.

  • Reissue API Key and Authentication Information

  • Fix Docker's public port settings.

  • Disable UPnP and remove port forwarding settings from the router.

  • Audits and penetration tests were conducted by an external security company.


This case demonstrates that development environments require the same level of security measures as production environments. Furthermore, it highlights that misconfigurations of development terminals and network equipment, not just cloud or container environments, can lead to serious incidents.


2. Fabrica Holdings subsidiary Media4u: Unauthorized access to SMS delivery system


On July 14, 2026, Media4u Co., Ltd. announced that it had experienced unauthorized access to its SMS delivery system. In this incident, the system was misused, resulting in the leakage of personal information and the sending of fraudulent SMS messages. Because the service infrastructure itself was misused, this became a serious incident that could potentially affect client companies and their customers.


Details of the damage

  • Unauthorized access to the SMS delivery system

  • Leakage of personal information

  • Unauthorized SMS messages sent by attackers

  • The parent company, Fabrica Holdings, also made this matter public.


Response status

  • We will conduct a system investigation and determine the cause.

  • Contact and respond to the affected customers.

  • They announced that they would report to the relevant authorities and take steps to prevent recurrence.


This incident demonstrated that a breach of a common infrastructure, such as an SMS delivery service, can lead not only to data leaks but also to secondary damage from fraudulent SMS transmissions. It is crucial for companies to continuously implement security measures that consider the entire service operation, including protecting administrator accounts, implementing multi-factor authentication, minimizing access privileges, and monitoring suspicious activity.



3. ANA Group's OCS: Cyberattack on "OCS FAMILY LINK SERVICE"


In July 2026, OCS Corporation, a member of the ANA Group, announced that its management and operation servers for "OCS FAMILY LINK SERVICE" had been subjected to an external cyberattack, potentially resulting in the leakage of some personal information and data. Following the discovery of the incident, the system was shut down as an emergency measure, and an investigation into the extent of the impact is ongoing.


Details of the damage

  • Cyberattack on management and operation servers

  • There is a possibility that some personal information and data may have been leaked to an external party.

  • We have temporarily suspended the service and are investigating the extent of the impact.


Response status

  • Emergency shutdown of the system and related networks.

  • Continue the investigation

  • Contacting affected customers and related companies individually

  • We will respond in cooperation with the police and related agencies.


This case demonstrates that when the servers supporting a service are compromised, it can lead not only to service disruption but also to the potential leakage of personal information and impact on users. It is crucial for companies to have server monitoring systems, anomaly detection, and rapid shutdown and recovery procedures in place beforehand. --- 4. Nakabayashi Co., Ltd.: Information leakage due to unauthorized access to product information website


In July 2026, Nakabayashi Co., Ltd. announced that its product information website had been illegally accessed by a third party, and that personal information stored on the site's servers may have been leaked to an external party.

In this case, the server environment hosting the website was targeted, potentially resulting in impacts on user information.


Details of the damage

  • Unauthorized access to product information website

  • Potential leakage of personal information stored on the server.

  • Service impact due to website downtime


Response status

  • The site in question has been shut down.

  • We will collaborate with external expert organizations to investigate the cause and scope of the impact.

  • Consultation and reporting to relevant organizations were carried out.


This case demonstrates that if a publicly accessible website or server is compromised, it can lead not only to website tampering but also to damage to the information stored within it.

For businesses, it is crucial to manage vulnerabilities in public servers, implement access control, avoid storing unnecessary information on servers, and establish a continuous monitoring system.



Cybersecurity measures that should be implemented on-site now


1. Conduct periodic inventories of publicly available assets.

In this Nakabayashi case, a publicly accessible website was targeted by unauthorized access, potentially leading to a data breach.

It is important for businesses to regularly monitor their assets that are exposed on the internet, such as global IP addresses, web servers, web applications, and APIs.

By conducting an inventory of publicly accessible assets approximately once a month, you can identify risks such as unmanaged servers (shadow IT) and outdated systems at an early stage.


"Not creating any publicly accessible internet assets that your company is unaware of" is a crucial first step in current cybersecurity measures.



2. Conduct regular incident response training.

Waiting until an actual cyberattack occurs to confirm the response system could lead to delays in the initial response.

It is important to conduct tabletop exercises a few times a year and to clarify the following roles in advance.

  • CSIRT (Incident Response Team)

  • Responsible for reporting to management.

  • Legal and Compliance Officer

  • Customer Service Representative

  • External presentation coordinator

By pre-determining communication channels, decision-makers, and information disclosure procedures after an attack is detected, it becomes possible to prevent further damage and achieve a rapid recovery.



What we can do for you with PIPELINE


Unauthorized access and vulnerability detection in publicly accessible assets: RiskSensor

To prevent damage from unauthorized access


RiskSensor automatically detects IT assets exposed on the internet (global IP addresses, web applications, API endpoints, etc.) and visualizes configuration errors and vulnerabilities.

This is also effective in identifying shadow IT and legacy systems, as revealed in this week's case studies.

Automated detection of externally exposed assets : Comprehensive visibility into domains, global IPs, and publicly accessible web applications. - Detection of misconfigurations : Automatically detects common configuration errors such as misconfigured Docker or router settings. - Detection of leaked credentials : Monitors email addresses and passwords leaked to the dark web and Pastevin. - Prioritization of attack surface : Scores detected risks and automatically calculates response priority.


Correlation analysis and detection of threats after a network breach: ThreatIDR

To detect internal system breaches early , ThreatIDR collects and analyzes logs from network security devices, firewalls, IDS/IPS, etc., to detect complex attack signatures. - Centralized log collection and analysis : Analyzes firewall, router, and IDS/IPS logs on a unified platform. - Threat correlation analysis : Correlates multiple security events to identify actual attacks. - Detection of anomalous access patterns : Detects unusual network communications to provide early warning of internal breaches. - SOC operation support : Prioritizes detected alerts to reduce investigation costs. - Incident investigation support : Identifies the scope of damage through retrospective analysis of past logs. Detailed monitoring and emergency response at the terminal level: PIPELINE MDR

To minimize damage from full-scale ransomware attacks and malware infections, PIPELINE MDR monitors Windows, macOS, and Linux devices 24/7, detecting, reporting, and conducting forensic investigations of suspicious behavior. - 24/7 monitoring of Windows/macOS/Linux devices : Multi-layered monitoring utilizing Microsoft Defender for Endpoint - Detection of suspicious behavior : Automatic detection of process anomalies, file tampering, and communication anomalies - Threat hunting : Proactive investigation of potentially compromised devices - Forensic investigation : Detailed investigation after an incident to identify the cause and scope of damage - Emergency response and recovery support : Support from containment after detection to recovery


Data breach risk assessment and response: DatalaiQ

To minimize data breaches across multiple companies , DatalaiQ classifies and analyzes potentially leaked data and assesses the actual level of leakage risk. - Data Classification: Automatically classifies leaked data, including personal information, authentication credentials, and confidential documents. - Visualization of Impact : Understand the number, type, and severity of leaked data. - Automatic Calculation of Response Priorities : Supports company-wide incident response decision-making.



sauce

1. [Important] Report and Apology Regarding a Security Incident Due to Unauthorized Access to the Development Environment - Wasabi Switch (formerly World Switch) | Support Manual (WASABI SWITCH Portal)

2. Notice and Apology Regarding Unauthorized Access and Information Leakage Due to Cyberattacks - 4193-20260714-01.pdf

3. [Notice] Regarding the temporary suspension of the "OCS FAMILY LINK SERVICE" service due to a system malfunction (Second Report) - https://www.ocs.co.jp/5282218

4. Nakabayashi - Regarding the possibility of unauthorized access and data leakage to our product introduction site "REVEX" [Second Report] - https://www.nakabayashi.co.jp/news/2026/info/1369





✦ Finally


Thank you for reading this far.

We at PIPELINE Corporation are a group of experts specializing in cybersecurity and threat intelligence.

We face threats together with our customers on-site every day.

"Even if we have a specialized team within the company, we lack the resources," "We don't know where to start," and "We want to prepare realistically, assuming we will be attacked."

We receive many inquiries like this. Regardless of the size of the company, the current situation is that weak points in defense are easily targeted.

Furthermore, trying to handle everything internally inevitably makes it easier for things to be overlooked.

That's why we focus on practical methods that are useful in the field, rather than idealistic theories, and propose a small-scale, easy-to-implement approach. Even "a small step within your capabilities" can make a big difference in safety.

If you have any concerns at all, please feel free to contact us. Let's work together to find the quickest way to strengthen your security.



Latest Articles

bottom of page