DAISEN Data Breach

Alleged

Ransomware claim involving DAISEN

Published: Aug 13, 2026
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
DAISEN
Industry
Technology
Date of Incident
Aug 13, 2026

Executive Summary

DAISEN, a technology company based in Japan, has been listed as a victim on the AiLock ransomware group’s dark web portal, with the listing published on August 13, 2026. The identification of this listing was made through SOCRadar’s Dark Web Monitoring service. DAISEN operates within Japan’s technology sector, and its domain, daisen.co.jp, is consistent with a domestic Japanese enterprise. AiLock has demonstrated a specific focus on Japan-based organizations in its recent operational period, indicating that this listing aligns with an identifiable geographic pattern of the threat actor. In the 60 days preceding this listing, AiLock claimed responsibility for 7 other victims, as documented on its leak portal. The group’s targeting pattern has predominantly included the Technology, Construction, and Manufacturing sectors. Geographically, its victim base is notably concentrated in Japan, the United States, and Mexico. Other recent AiLock victims that share similarities with DAISEN’s profile, such as Japanese technology or manufacturing organizations, include Yaomasa, WBF Construction, Pinturas Prisa, and Richmont Graduate University. The fact that DAISEN and Yaomasa were listed on the same date suggests a potential coordinated publication or a batch-release strategy by the AiLock portal operators.

Technical Analysis

Initial-access correlation against SOCRadar’s stealer-log telemetry returned no records specifically for daisen.co.jp within the queried dataset. It is crucial to understand that a null result from this specific query does not equate to a confirmation of a clean environment. Potential credential exposure could still exist in other data feeds not included in this particular dataset, may be associated with alternative or unquerged corporate domains, or could be linked to personal email accounts that were utilized for corporate access. Therefore, the absence of data in this query serves as an indicator for continued monitoring rather than definitive proof of a secure environment. For ransomware groups like AiLock, infostealer-harvested credentials represent a well-documented pathway for initial access. Threat actors or initial access brokers typically source recent credential logs from underground marketplaces. These credentials are then validated and used to gain unauthorized access to corporate systems, often through VPNs, remote desktop protocols, or cloud portals, before the deployment of ransomware. The absence of direct evidence in this query does not preclude this scenario; credentials might have appeared in feeds outside the scope of this specific dataset, could have been used and subsequently rotated before indexing, or may have been harvested using personal email aliases. Security teams are advised to prioritize ongoing monitoring and proactive credential hygiene checks rather than relying on a null query as an indicator of exoneration.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.