Fujitsu said in March 2024 that it had detected malware across several of its systems. The company reported that the malware was installed on one business computer and spread to others on its internal network in Japan, and that it executed commands to copy files containing personal information and customer business information.
The company described the malware as not being ransomware, and as using techniques that made it hard to detect. It apologised to customers and published the results of its investigation later in the year.
No Encryption Means No Deadline
Ransomware announces itself. It has to: the business model needs the victim to know, quickly, so the clock can start.
Malware that only copies has the opposite requirement. It succeeds by remaining unremarkable, and the organisation finds out through detection rather than through a note. That makes the discovery date a property of the monitoring, not of the intrusion.
What A Technology Supplier Holds
Fujitsu builds and runs systems for other organisations, including governments. Files describing customer business sit on its internal network as a condition of doing the work.
Graded medium: the company disclosed the mechanism in general terms without naming affected customers, publishing a record count, or describing how the first machine was reached.
Compiled from Fujitsu’s notices and public reporting, listed below. No entry route, affected-customer list or record count was published. No actor has been identified. Corrections: corrections@forensicpost.com.