Scala Communications i-ask FAQ platform breach (Daiwa / Citizen / Sompo)

Scala Communications i-ask FAQ platform breach (Daiwa / Citizen / Sompo)

On October 6, 2026, Scala Inc. (TSE Standard: 4845) disclosed that a third party had gained unauthorized access to "i-ask", the FAQ and inquiry-management system run by its consolidated subsidiary Scala Communications Inc. (SC). According to Scala, the intruder logged in to the i-ask admin site without authorization and installed an "unauthorized program" (不正なプログラム) on an SC-managed server. The intruder may then have obtained inquiry information from the databases of client-company environments running on that same server.

Scala puts the exposure at up to 713,126 inquiry records. That figure is a cumulative count per inquiry and includes repeat inquiries from the same customer. It is not a count of people. The records span up to five client companies, and Scala is still name-matching (名寄せ) them to find the actual number of affected individuals. Scala has declined to name its clients.

Three companies have since confirmed in their own notices that they were affected:

  • Daiwa Securities Co. Ltd. (October 5)
  • Citizen Watch Co., Ltd., for the Citizen, Bulova and Frederique Constant inquiry forms (October 6)
  • Sompo Japan Insurance Inc., for its SMILING ROAD business dashcam service (October 7)

The remaining affected clients (up to two) have not been identified. The first tenant disclosure (Daiwa, October 5) came a day before the vendor's own public notice (October 6).

No CVE, CISA KEV entry or CVSS score is associated with this incident. This is a compromise of a vendor-operated hosted platform, not a disclosed software vulnerability.

Technical Information

What happened

Scala's IR notice of October 6 and SC's notice on its own site the same day describe the incident in nearly identical terms:

"We have confirmed that a third party unauthorizedly logged in to the i-ask admin site, installed an unauthorized program on a server managed by Scala Communications, and may then have obtained inquiry information from the databases of client companies' system environments running on the same server."

  • Platform: i-ask is SC's FAQ system for company websites. It publishes frequently asked questions and answers and also manages customer inquiries.
  • Window: Scala says the unauthorized access ran from around 20:30 on Friday, October 2 to around 08:00 on Saturday, October 3, 2026 (JST). The affected tenants quote SC with more precise times: 20:33 on October 2 to 08:01 on October 3 JST, which is roughly 11:33 to 23:01 UTC on October 2.
  • Detection: on the morning of October 3, a database monitoring alert prompted SC to start investigating.
  • Containment: SC cut off the unauthorized access at about 08:00 JST on October 3. It sent a first report to the affected client companies the same day. Daiwa, Citizen and Sompo each say they were notified on October 3.
  • Data types (Scala): name, email address, inquiry content and other fields. The exact set varies by client.
  • Cross-tenant reach: the data came from the databases of several client environments hosted on the same SC-managed server. Scala has not described exactly how the intruder moved from the admin site to those databases.

What is confirmed and what is not

  • Access method: undisclosed. Scala says only that the attacker "unauthorizedly logged in to the i-ask admin site." One of SC's fixes was changing the password of "the account used for the unauthorized login", so a specific account was used. Scala has not said how the attacker got working access to it.
  • Program type: undisclosed. Scala calls it an "unauthorized program". It has not given a type, family or name.
  • Attribution and extortion: none disclosed. No threat actor, ransom demand or leak-site claim appears in any primary source.
  • Secondary misuse: none confirmed. None had been confirmed as of each notice date (Scala, Daiwa, Citizen, Sompo). Daiwa and Sompo also report no confirmed publication of the data online.
  • Tenants' own systems: not accessed. Daiwa, Citizen and Sompo each say their own systems were not accessed.
  • Total number of people affected: unknown. Scala is still name-matching the records. A people total cannot be calculated from the published figures (see below).

Timeline (JST)

  • Oct 2, 2026, ~20:30 (tenants quote ~20:33): unauthorized login to the i-ask admin site begins. The unauthorized program is installed on the SC-managed server (exact install time not disclosed).
  • Oct 3, morning: a database monitoring alert prompts SC to start investigating.
  • Oct 3, ~08:00 (tenants quote ~08:01): unauthorized access is cut off.
  • Oct 3: SC sends a first report to affected client companies.
  • Oct 5: Daiwa Securities Co. Ltd. discloses. Its notice is published through Daiwa Securities Group (8601) IR channels, and affected customers are contacted individually.
  • Oct 6: Scala Inc. publishes its IR notice and SC posts its own site notice. This is the first vendor disclosure. Citizen Watch discloses the same day.
  • Oct 7: Sompo Japan discloses.
  • Mid-October 2026 (planned): Citizen says it will stop using the system and delete all customer personal data stored on it. Citizen says this phase-out was already underway before the incident.

Affected Product Versions

Not applicable in the CVE sense. There is no vulnerable software version to patch. The affected asset is SC's hosted i-ask FAQ and inquiry platform. Client companies used it to receive questions from their customers through website inquiry forms.

The key architectural fact is the shared-server tenant model. Scala says the client environments ran on the same SC-managed server. A single unauthorized admin-site login, followed by a single unauthorized program, reached the inquiry databases of up to five client environments. SC changed administrator passwords across all environments as part of its response.

Only companies that confirmed it in their own notices are listed below:

Affected company (own notice)

Service / forms

Count

Unit

Data fields reported

Daiwa Securities Co. Ltd. (Oct 5)

Customer inquiries

~110,000; also ~220,000

People (customers); ~220,000 is records, counting inquiries with no personally identifying info

Name, email address, account number, etc.

Citizen Watch Co., Ltd. (Oct 6)

Citizen, Bulova and Frederique Constant website inquiry forms

~100,000

People (約10万名分)

Name, address, phone number, email address, etc. Bank-account or credit-card details may also be exposed if customers typed them into the free-text inquiry field

Sompo Japan Insurance Inc. (Oct 7)

SMILING ROAD business dashcam service

~60,000

Records, counted per inquiry and including duplicates (約6万件), not people

Name, phone, address, email, employer details (company, department, industry, agent name, etc.), driver ID, driving-alert information, device information (e.g. dashcam serial number), application number, inquiry content

Notes by company:

  • Daiwa says SC reported traces of unauthorized access to and acquisition of Daiwa customer information. Daiwa says the data cannot be used to access customers' securities accounts or to trade, including through online trading, and no unauthorized transactions have been confirmed.
  • Citizen says its own EC site, MY CITIZEN, Citizen Owners Club, production systems and internal network were not accessed. It has not given a per-brand breakdown.
  • Sompo says the data subjects are mainly employees of corporate customers that use SMILING ROAD. It says no bank-account, credit-card or My Number card information is included.
  • Unidentified clients: Scala says up to five client environments were affected. Three companies have disclosed. The rest (up to two) are unknown.
  • Tobu Railway (context only, not counted as affected): Tobu said it uses an SC service for its customer-centre inquiry form. SC told Tobu that, so far, it has found no trace of Tobu-related information being viewed or obtained. Tobu's notice does not mention i-ask.

Units warning: these figures use different units and overlap, so they cannot be added together. Daiwa's ~110,000 and Citizen's ~100,000 count people. Sompo's ~60,000, Daiwa's ~220,000 and Scala's 713,126 count records that include duplicates. No reliable total of affected people can be derived until Scala finishes name-matching.

Workaround and Mitigation

Vendor response (Scala / SC)

Scala reports these containment and remediation steps:

  • Changed the password of the account used for the unauthorized login.
  • Blocked access from the attacking IP addresses.
  • Quarantined the installed unauthorized program.
  • Changed administrator-account passwords across all environments.
  • Changed settings so that uploaded files cannot be executed as programs.
  • Is monitoring continuously.
  • Started a forensic investigation with an external specialist firm.
  • Reported the incident to Japan's Personal Information Protection Commission (PPC).
  • Consulted the police and pledged full cooperation with the investigation. Scala describes this as consulting the police, not filing a formal complaint.
  • Set up a group-level task force at the parent company.

SC's planned measures

SC's site notice says it will introduce:

  • Stronger administrator authentication, including multi-factor authentication (MFA)
  • Separation between environments
  • Stronger monitoring
  • Regular vulnerability assessments by an outside party

SC also warns of phishing that impersonates SC or its client companies.

Tenant actions

  • Daiwa has contacted affected customers individually and set up a hotline. It is reviewing its existing outsourcing vendors and its overall approach to vendor management.
  • Citizen has reported to the PPC, as has SC, and has consulted its local police. It has set up a dedicated inquiry form. Citizen also says the system is no longer used for new inquiries and that stored data will be deleted when its use ends in mid-October 2026.
  • Sompo is contacting affected customers individually, has set up a hotline and is reviewing vendor management.

Recommended actions for organizations

  • Confirm exposure. If you use SC services for inquiry forms or FAQs, ask SC directly whether your environment was among those on the affected server, and what data it held.
  • Prepare for phishing. Exposed names, email addresses and inquiry histories are well suited to convincing lures. Warn customers and frontline staff about messages that pretend to come from you or your vendor, as SC itself has warned.
  • Treat free-text inquiry fields as sensitive data. Citizen notes that customers may have typed bank or card details into the inquiry box. Review what your web forms collect and how long the vendor keeps it.
  • Check retention and offboarding. Citizen was already phasing out the system and still had customer data on it. When you leave a vendor, verify that the data is actually deleted.
  • Test your vendors against the controls this incident exposed:
    • MFA on vendor admin consoles
    • Isolation between tenants or environments
    • Blocking execution of uploaded files
    • Database activity monitoring with alerting
    • IP allow-listing for admin sites
    • Regular third-party penetration testing
  • Ask about hosting topology, not just certifications. Ask vendors which other customers share your server or database host, whether the admin plane is shared across tenants, and whether admins can upload executable content.
  • Set notification terms in contracts. Include vendor-to-customer notification SLAs and coordination of public statements. Here, a tenant disclosed publicly before the vendor did.

Indicators of Compromise

No indicators of compromise have been publicly disclosed. Scala says it blocked the attacking IP addresses but has not published them. No primary source has released file hashes, domains, IP addresses, file names or details of the unauthorized program. No vendor, tenant, government or research source has published a MITRE ATT&CK mapping for this incident.

We will not list unverified indicators. We will update this advisory if Scala, SC or an affected tenant publishes technical indicators or forensic findings.

Why This Matters for Your Third-Party Risk Program

An FAQ and inquiry-form tool rarely ranks high on a vendor-risk register. Yet one unauthorized admin-site login on a single shared server put free-text customer data from up to five companies within reach, including account numbers, home addresses, driver IDs and possibly card details typed into a "contact us" box, and it turned one vendor's incident into separate breach notices at Daiwa, Citizen and Sompo.

See which of your vendors carry this kind of multi-tenant concentration risk: Book a demo.

Not the person who owns vendor risk at your organization? Forward this advisory to your TPRM lead with one question: which of our customer-facing web-form, FAQ and chatbot vendors hold our customers' data on shared, multi-tenant infrastructure?

Contact us / Book a demo

Talk to Rescana about this advisory, or book a demo of the platform.