Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedMulti-Stage ChainPIIIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Yonex Corporation
bd_cf9e249c35c5a4d4 · schema v1 · pii pii-v1
Full breach record for Yonex Corporation →Yonex Corporation notified affected individuals that an unauthorized third party accessed employee email accounts via phishing between June 9 and September 12, 2022. The attacker viewed names and credit card numbers in October 2022. No data was downloaded. Yonex engaged forensic investigators, reset passwords, and is implementing MFA.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_7e1f303ef9fb4655Montana State AGfiled 2022-11-21Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/yonex-corporation-20221121.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 21, 2022
- Raw hash
- cecc964e9a54a22031e68f92af739885c9bd4027a1e01c46bd071d9c57ce08bf
Reporting entity
- Name
- Yonex Corporationnorm: yonex
Victim entity
- Name
- Yonex Corporationnorm: yonex
Incident
- Discovered
- Oct 26, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 26 days(26 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.