Skip to content
>_ITDITDWeb Security Platform

Security Guides

Daiwa Securities vendor breach (about 110,000 customers, 220,000 records): what may have leaked and what customers should do

Unauthorized access to a vendor server that Daiwa Securities uses to manage online inquiries may have leaked names, emails and account numbers of about 110,000 customers. What may have leaked, what did not, and what to do today.

Published 2026-10-06 Updated 2026-10-06 Last verified 2026-10-06 11 min read

For: people with a Daiwa Securities account who have contacted the company online, and businesses that use outside services to handle customer inquiries. This article is based on the official notice from Daiwa Securities Co. Ltd. and does not cover attack techniques.

What customers should do today

1

Check whether you are affected in your message box

According to the company's website, affected customers were contacted individually on October 5 through the message box (お知らせBOX) in online trading. Sign in yourself from a bookmark or the official app, not from a link in an email, and check there.

If you are unsure, call the dedicated line (0120-851850, 9 a.m. to 5 p.m. Japan time, closed weekends and holidays). Use the number published on the company's official site, not one given in a message you received.

2

Never log in from links in emails or texts

What may have leaked is your name, email address, account number and the content of your inquiries. Together, these make it possible to write a fake message with the right name, the right account number, and a reference to your past inquiry.

The company's phishing page tells customers not to log in to online trading from emails. Even if a message talks about a security check, an apology or compensation, do not open the link; sign in from your usual bookmark or the official app (how to spot fakes: What is phishing?).

3

Never give anyone your ID, password, PIN or one-time passwords

The company asks customers not to give their trading ID, password, PIN or one-time passwords in response to suspicious messages. The same applies if a caller says it is "to confirm your identity".

A caller who knows your name and account number has not proved anything. That is exactly the information that may have leaked.

4

Sign in with a passkey, and check operation notifications

The company offers passkey sign-in to online trading, using a fingerprint or face recognition. A passkey only works on the real site, so it helps prevent the damage that follows from typing your ID and password into a fake site (how it works: What is a passkey?; compared with other methods: Choosing MFA the right way).

Also confirm that operation notifications are on. These emails arrive when someone signs in, trades, withdraws money or changes personal details. The company says it switched them on for, in principle, all customers from May 11, 2025.

5

Look through your operation history

After signing in to online trading, open the "お手続き・サポート" (procedures and support) menu and choose "操作履歴" (operation history) to see recent sign-ins and procedures.

If you see a sign-in, trade or change you did not make, change your password at once and contact the company. If you use the same password elsewhere, separate it there too (how to check: How to check if your password has leaked).

What happened (from Daiwa Securities' notice)

Daiwa Securities Co. Ltd. published a notice on October 5, 2026 about the possible leak of customer information through unauthorized access to an outside vendor. Everything below is from that notice.

  1. About 8:33 p.m., October 2 to 8:01 a.m., October 3, 2026

    According to the vendor, unauthorized access to the vendor's server took place during this window.
  2. October 3

    The vendor told the company it had found traces of access to and retrieval of the company's customer information.
  3. October 5

    The company announced the incident and contacted affected customers individually through the online-trading message box.
~110,000
Customers whose name, email, account number etc. may have leaked
~220,000
Records in total, including inquiries that identify no one
Not found
Unauthorized access to the company's own systems
Not found
Fraudulent trades, publication or spread of the data (as of Oct 5)
What may have leaked (from Daiwa Securities' notice)
Where
The server of the vendor providing the service the company uses to manage customers' online inquiries
Scope
Inquiry-related data for about 110,000 customers; about 220,000 records including inquiries that identify no one
Items
Name, email address, account number and other information from records of inquiries already received
Accounts
The company says this data cannot be used to access securities accounts or trade, including through online trading
Company systems
The access was only to the vendor's server; no unauthorized access to the company's systems was found
Cause
Not disclosed. The company says it will review the vendor's root-cause investigation
Vendor's response
The vendor reported emergency security hardening and no further unauthorized access or leaks found so far
Contact
Dedicated line 0120-851850 (9 a.m. to 5 p.m. Japan time, closed weekends and holidays)

What the leaked data could be used for

None of these items is rare on its own, but together they make fake messages look real. What sets this case apart is that, beyond name and contact details, it includes account numbers and what customers asked about.

Name + email + account number

↓

Fake sign-in requests with the right name and account number

→ Never log in from links / use a passkey

Name + past inquiry content

↓

Fake calls or emails starting "About your recent inquiry…"

→ Never give a PIN or one-time password / call back on the official number

Combinations of data that may have leaked, and the matching action for customers

Not found, according to the notice

  • Access to the company's own systems
  • Fraudulent trades (as of October 5)
  • Publication or spread of the data (as of October 5)
  • Account access or trading with this data alone (the company says it is not possible)

May have leaked

  • Name
  • Email address
  • Account number and other details
  • Inquiry content (records of inquiries already received)

How to read it: 'this data cannot be used to trade' does not mean 'do nothing'

The company says the data that may have leaked is not enough on its own to access accounts or trade. That means this data alone is not enough.

If you type your ID and password into a fake email or site, it is a different story. Japan's Financial Services Agency has warned that fraudulent trades using login IDs and passwords stolen through fake sites posing as securities firms have been frequent (FSA warning, Japanese). Login details are the likely next target, so never logging in from links and using a passkey are the core defenses.

Inquiry content differs from person to person. If you remember what you asked about, you can tell when a message mentions that topic and suspect the leaked data is being used.

For businesses that use outside services for customer inquiries

The data was stored not in the company's own systems but on the server of a vendor used for inquiry management. The cause has not been disclosed, so this section sticks to points that apply to any similar setup. A case where the help-desk system itself was the target of an intrusion is covered in the DIVD incident. Here we add what is specific to inquiry records.

1

Do not let inquiry forms collect account numbers as free text

In the message field of an inquiry form, customers often type account numbers, dates of birth, and sometimes even passwords. If identity checks are needed, have customers send inquiries from a signed-in screen, and do not store the numbers in inquiry records.

A first step is to detect strings shaped like account or phone numbers when a form is submitted and mask part of them before saving. Some inquiry-management services offer redaction of sensitive data or a way to process content before it is stored.

2

Set a retention period for closed inquiries and delete them when it ends

Once an inquiry is closed, its record is rarely used, but in a leak every record is exposed. Decide how long to keep old records and make them delete automatically when the period ends.

If a vendor stores them, set the retention period and deletion method in the contract and check at least once a year that deletion actually happens. A case where data was not deleted after a contract ended is in the ApplyNow entry of the 2026 incident list.

3

List the vendors holding customer data, with volumes and a notification deadline

List every outside service that holds customer or applicant data: inquiry management, email delivery, surveys, recruiting and so on. For each, write down how many records and which items it holds, and within how many hours it must tell you if it detects unauthorized access.

Starting with the vendors that hold the most records, check that their admin screens have multi-factor authentication, source restrictions and alerts on large exports (background: Authentication vs authorization).

Sources (public record)

The facts in this article are based on the public information below. We do not speculate about undisclosed methods or causes.

  • Daiwa Securities Co. Ltd., notice on the possible leak of customer information due to unauthorized access to an outside vendor (October 5, 2026, Japanese) — company disclosure (PDF)
  • Daiwa Securities website notice (individual contact through the message box, Japanese) — daiwa.jp
  • Daiwa Securities, phishing warning (Japanese) — daiwa.jp
  • Daiwa Securities, security settings (passkeys, operation notifications, operation history; Japanese) — daiwa.jp
  • Financial Services Agency, warning on unauthorized access and fraudulent trades in online trading (Japanese) — fsa.go.jp
  • Nikkei (October 5, 2026, Japanese) — nikkei.com
  • Kyodo News (October 5, 2026, via Yahoo! News Japan, Japanese) — news.yahoo.co.jp

Update history

2026-10-06: First version, based on Daiwa Securities' notice of October 5. The company says it will review the vendor's root-cause investigation; this article will be updated when new facts are published.

FAQ

QWhat was leaked in the Daiwa Securities breach?
A

According to Daiwa Securities' notice of October 5, 2026, names, email addresses, account numbers and other information about 110,000 customers, taken from records of their online inquiries, may have leaked. Including inquiries that identify no one, about 220,000 records are involved. The data was stored on the server of a vendor whose service the company uses to manage inquiries.

QWere login IDs or passwords leaked?
A

The company says the data that may have leaked cannot be used to access securities accounts or to trade with the company, including through online trading. The notice lists names, email addresses and account numbers as the items that may have leaked, and does not list trading IDs or passwords. It also asks customers never to give anyone their trading ID, password, PIN or one-time passwords.

QAm I affected?
A

According to the company's website, affected customers were contacted individually on October 5 through the message box (お知らせBOX) in online trading. Sign in yourself from a bookmark or the official app and check the message box. If you are unsure, call the dedicated line (0120-851850, 9 a.m. to 5 p.m. Japan time, closed weekends and holidays).

QHave there been fraudulent trades?
A

The company says that as of October 5, no fraudulent trades caused by this incident had been found, and the data had not been found published or spread on the internet. It says it will keep monitoring.

QWhat scams should I watch for?
A

The company warns of phone and email scams that use customers' names and inquiry details while posing as the company or related parties. A message that correctly mentions your past inquiry or your account number is not proof it is genuine. Do not open links or attachments; check any unfamiliar message or trade with a contact point you found yourself on the official website.

QWhat caused the breach?
A

As of October 6, 2026, the cause and the method had not been disclosed. The company says it will review the vendor's root-cause investigation and permanent fixes, check its other existing vendors and re-examine how it manages vendors.