Data breach
Dentsu
- Records
- 12,555
- Breach date
- 31 May 2023Estimated
- Added
- 5 December 2024
What was exposed
5 types of data · 1 puts you at serious risk
- Names12,555
- Home addresses12,555
- Social security numbers12,422
- Phone numbers5,091
- Email addresses3,566
About this breach
Our investigation team has indexed a dataset tied to Dentsu containing records for 12,555 individuals, with an estimated attack date of May 31, 2023. The listing was added to our database on December 5, 2024. No ransomware group or individual actor has publicly claimed responsibility. Separately, Information Services International-Dentsu (ISID), a Dentsu Group company, disclosed in June 2023 that an external attacker gained unauthorized access to its remote access equipment and possibly leaked personal information from its account management system. The connection between the indexed dataset and the ISID disclosure has not been confirmed, but both fall in the same period and involve the same corporate group.
Breach Timeline
May 9, 2023: ISID detected an external attack on remote access equipment used by the company and its group companies, and implemented countermeasures the same day, according to the company's notice.
May 16, 2023: ISID reported the incident to Japan's Personal Information Protection Commission and the Japan Information Technology Services Industry Association.
June 2, 2023: ISID sent emails to individuals whose personal information may have been leaked, per the company notice.
June 6, 2023: ISID published a notice confirming the possibility of a leak of 13,706 data items across three categories.
What Information Was Compromised?
Our analysis found the following data types in this breach: names (12,555 records), home addresses (12,555 records), Social Security numbers (12,422 records), phone numbers (5,091 records), and email addresses (3,566 records).
ISID's June 6, 2023 notice listed additional fields tied to its own incident: employee and development partner user IDs, email addresses, names in Japanese and Latin characters, department names, organization codes, employee codes, and the email addresses of clients and business partners.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
A name and home address alone can enable targeted phishing, fake delivery scams, and convincing impersonation attempts. When combined with a Social Security number, the risk shifts toward identity theft: fraudulent loan or credit applications, tax-related fraud, and account takeovers that rely on personal details to pass security questions. Phone numbers in a breach are commonly used for smishing, which is phishing by text message, and for voice scams that reference real personal information to appear legitimate. Because this listing includes several high-sensitivity fields together, affected individuals should treat the exposure as more than a routine email leak.
What Is Dentsu Doing in Response?
Based on ISID's published notice, the company contacted the vendor of the affected remote access equipment and a cybersecurity specialist and implemented countermeasures on the day the attack was detected. It investigated the unauthorized access to its account management system, notified affected individuals by email on June 2, 2023, and reported the incident to Japanese regulators on May 16, 2023. ISID stated at the time that it had not confirmed unauthorized access to servers other than the one in its account management system, and said it would disclose further findings on its website. As of September 25, 2026, we have not identified a public notice from Dentsu itself addressing the indexed dataset, and no actor has come forward.
What Should You Do If You Were Affected?
Place a fraud alert or credit freeze with the major credit bureaus, especially if your Social Security number was exposed.
Review your bank, credit card, and tax records for unfamiliar activity, and consider an IRS Identity Protection PIN if you are a US taxpayer.
Be cautious with unexpected calls, texts, or emails that reference your name or address; attackers use breached details to seem credible.
Change passwords on any accounts tied to exposed email addresses and enable multi-factor authentication where available.
