
Japan-based Nippon Steel Solutions said it suffered a significant data security incident caused by the exploitation of a zero-day vulnerability in software used for daily operations.
Nippon Steel Solutions (NS Solutions), a subsidiary of Nippon Steel Corporation, provides IT services including consulting, system integration, cloud computing, cybersecurity, and infrastructure solutions for various industries.
On July 8, in a data security incident notice published on its website, NSS said that on March 7, it detected unauthorised access within its internal server. The company immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.
NSS also took steps to secure the affected server and isolated it from the internal network.
“After that, while conducting an impact range investigation with the advice of external experts, signs of unauthorised access by a third party were confirmed, and some of the personal information of customers, partners, and our employees stored in our internal server were out of the company. It was found that it may have been leaked to the department. In addition, there is no impact on the cloud services provided by our company to customers.
“As for the cause of unauthorised access, it has been found that there was a zero-day attack on network equipment,” NSS said.
The compromised data included names, company names, affiliations, positions, company addresses, business email addresses, phone numbers, business email addresses and more.
NSS said it has notified relevant law enforcement authorities about the incident including the Personal Information Protection Committee.
“Regarding this case, there is no trace of information spreading and circulating on SNS and the dark web at the moment, and secondary damage such as the abuse of leaked personal information has not been confirmed,” the company added.
At the time of publishing, no known hacker group claimed responsibility for the cyber attack on NSS. The company also did not share details on who was behind the attack, how much data was compromised, or whether it has received a ransom demand.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543