Ransomware victim disclosure
← All victimsKADOKAWA Corporation
Claimed by Blacksuit · listed 2 years ago
Status timeline
- ListedJun 27, 2024
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileKADOKAWA Corporation is a major Japanese publishing and media conglomerate headquartered in Tokyo. The company publishes novels, manga, light novels, magazines, and produces anime and video game content across multiple imprints and subsidiaries including Dwango and NicoNico (a video streaming platform).
- Industry
- Publishing & Media
Attack summary
Severity: high — Operational disruption to a major Japanese media conglomerate with significant business impact across multiple subsidiaries and digital platforms (NicoNico is a major video platform). Network-wide encryption of connected infrastructure indicates substantial systems compromise. No exfiltration proof published in excerpt, but operational impact is confirmed.Blacksuit claims to have gained access to KADOKAWA's network approximately one month before the disclosure and encrypted multiple connected subsidiary networks including Dwango, NicoNico, and the main KADOKAWA infrastructure via compromised hypervisor control points (vSphere/ESXi). No exfiltration is explicitly claimed in the leaked post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Network-wide encryption across multiple subsidiaries
- Corporate infrastructure (vSphere/ESXi systems)
- Subsidiary systems (Dwango, NicoNico)
What the group claims
Our team gained access to the Kadokawa network almost a month ago. It took some time, because of the language, to figure out that Kadokawa subsidiaries' networks were connected to each other and to get through all the mess Kadokawa's IT department made there. We have discovered that Kadokawa networks architecture was not organised properly. It was different networks connected to the one big Kadokawas infrastructure being controlled through global control points, such as eSXI and V-sphere. Once we have gained access to the control center we have encrypted the whole network (Dwango, NicoNico, Kadokawa, other subsidiaries).
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

