ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Dentsu confirms cyberattack on U.S. subsidiary Merkle exposed employee and client data

Japanese advertising and public relations giant Dentsu Group has confirmed that its U.S.-based subsidiary Merkle suffered a cybersecurity incident that exposed sensitive information belonging to employees, clients, and suppliers.


The company detected abnormal activity within Merkle’s network earlier this month, prompting an immediate shutdown of certain systems and the launch of a full-scale investigation. Dentsu said the affected systems were isolated as part of its incident response plan to contain the breach and minimize potential damage.


“We detected abnormal activity within part of the network of Merkle, a company leading the customer experience management area of our group’s overseas business,” Dentsu said in an official statement. “We immediately initiated our incident response procedures, proactively shut down certain systems as a precaution, and took swift measures to minimize the impact.”


Merkle, headquartered in Columbia, Maryland, operates as a data-driven customer experience and marketing agency under Dentsu’s international network. The subsidiary employs roughly 16,000 people across North America, Europe, the Middle East, and Asia-Pacific, and serves global brands including Microsoft, American Express, Nestlé, Hilton, Intel, and Diageo.


According to Dentsu, the breach resulted in the theft of files containing data on current and former employees, as well as some clients and suppliers. The compromised information reportedly includes payroll and salary details, bank account numbers, National Insurance identifiers, and personal contact information. While the company has not confirmed how many individuals were affected, its U.K. workforce alone numbers more than 2,500 employees, and the total number of exposed records could be significantly higher.


A Dentsu spokesperson confirmed hat data was stolen and that impacted individuals are being notified. “A review of those files determined that they contained information relating to some clients, suppliers, and current and former employees,” the spokesperson said.


Dentsu circulated an internal memo informing staff about the exposure of payroll and personal data. The company also said it has “taken measures to prevent the public disclosure of the data,” though it did not specify whether ransom negotiations took place. At this stage, no ransomware group has claimed responsibility for the breach.


Dentsu has engaged third-party cybersecurity specialists to assist with the investigation and strengthen its network defenses. It also notified law enforcement agencies, the United Kingdom’s Information Commissioner’s Office (ICO), and the National Cyber Security Centre (NCSC).


The Tokyo-based firm emphasized that its Japan-based systems remain unaffected, though it expects the incident to have “some financial impact.” The company continues to assess the full scale and consequences of the breach. With global revenue of approximately $8 billion and more than 60,000 employees worldwide, Dentsu ranks among the world’s five largest advertising networks.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543