Security News > 2021 > May > Fujitsu pulls ProjectWEB tool offline after apparent supply chain attack sees Japanese infosec agency data stolen

A Fujitsu project management suite is causing red faces at the Japanese company's HQ after "Unauthorised access" resulted in data being stolen from government agencies, local reports say.
The firm's ProjectWEB tool was reportedly accessed by an unidentified "Third party" who helped themself to data from, among others, Japan's Ministry of Foreign Affairs, its Cabinet Office Cyber Security Centre and the Ministry of Land.
Fujitsu has shut down ProjectWEB and pulled it offline.
The Japan Broadcasting Association, the local equivalent of the BBC, reported that on 20 May data was stolen through a ProjectWEB deployment used in Tokyo Narita airport, the capital's main international hub.
"Oz Alashe, chief exec of behavioural security platform CybSafe, commented:"The attack on these Japanese government agencies is a stark reminder of the cyber risks posed by the supply chain.
Securing their own networks, data and users is a challenge in itself for organisations, and the threat of data loss and compromise via third parties in the supply chain adds a new layer of complexity to the equation.
News URL
Related news
- Recent GitHub supply chain attack traced to leaked SpotBugs token (source)
- SpotBugs Access Token Theft Identified as Root Cause of GitHub Supply Chain Attack (source)
- That massive GitHub supply chain attack? It all started with a stolen SpotBugs token (source)
- Infosec experts fear China could retaliate against tariffs with a Typhoon attack (source)
- Active! Mail RCE flaw exploited in attacks on Japanese orgs (source)
- Ripple's xrpl.js npm Package Backdoored to Steal Private Keys in Major Supply Chain Attack (source)
- Ripple NPM supply chain attack hunts for private keys (source)
- Magento supply chain attack compromises hundreds of e-stores (source)
- Malicious Go Modules Deliver Disk-Wiping Linux Malware in Advanced Supply Chain Attack (source)
- Supply chain attack hits npm package with 45,000 weekly downloads (source)