October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Nidec Confirms Data Theft at Vietnam Subsidiary After 2024 Ransom Demand

Nidec Precision Vietnam suffered a 2024 data-extortion incident involving 50,694 files, but Nidec reported no file encryption or confirmed wider group impact.
From TheFinanceBase Team4 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Nidec Precision Vietnam Co., Ltd. (NPCV), a Nidec subsidiary, confirmed that attackers stole files and demanded a ransom in August 2024. Nidec said 50,694 files were exposed or could not be ruled out as viewed, and that the attackers published stolen material after the company refused to pay. Nidec reported no file encryption and said its investigation found no confirmed impact at other Nidec group companies.

What happened at Nidec Precision Vietnam?

The incident affected NPCV, not a publicly confirmed compromise of Nidec Corporation’s entire global network. Nidec’s detailed account describes unauthorized access, theft of files, a ransom demand and publication of stolen data. Its October 17, 2024 notice says no files were encrypted.

Date What Nidec reported
August 5, 2024 NPCV received a message from an external criminal group claiming it had entered the network and stolen documents and files, followed by a ransom demand.
August 9, 2024 Nidec confirmed that material believed to have been stolen from NPCV had appeared on a leak site and could be downloaded.
August 12, 2024 Nidec issued its first public notice about the incident.
August 15, 2024 NPCV reported the information leak to local police in Vietnam.
September 6, 2024 NPCV reported the incident to Vietnam’s Ministry of Public Security cybercrime authorities under applicable personal-data rules.
September 7–12, 2024 Nidec observed further information being posted and filed an additional report concerning the leak.
October 17, 2024 Nidec Precision published a detailed second report, including the file count and data categories.

Nidec Precision’s October 17, 2024 incident report is the company’s account of the timeline and findings. SecurityWeek covered the disclosure on October 21, 2024; neither date represents a new incident in 2026.

What information was exposed?

Nidec identified 50,694 files that had been exposed or could not be completely ruled out as having been viewed. That is a file count, not a count of affected people. The company described a mix of business and operational records:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • NPCV internal documents
  • Letters from business partners
  • Green-procurement materials
  • Occupational health and safety documents
  • Business and supply-chain policy documents
  • Transaction records, including purchase orders, invoices and receipts
  • Contracts

Nidec said it would contact affected business partners individually. Its public notice does not provide a file-by-file inventory, identify every data subject, or state how many individuals’ personal information—if any—was involved. The fact that NPCV notified Vietnamese authorities under personal-data rules does not by itself establish a specific number or type of personal records exposed.

Was this really a ransomware attack?

Media coverage called the event a ransomware attack, but the company’s disclosed facts point more precisely to data theft and extortion: attackers demanded payment to prevent release of files, Nidec refused, and stolen material was published. Nidec explicitly reported no file encryption. The public account does not establish that systems were locked, production was stopped, or operations were disrupted.

This distinction matters because a data-extortion incident can expose commercial documents even without the encryption phase commonly associated with ransomware. Nidec also said it found no further intrusion after publication.

How did attackers get access?

Nidec said its investigation believed attackers obtained the user ID and password for an NPCV general domain account by an unknown method, then accessed a server and stole files available through that account. The company identified VPN equipment as a suspected entry point and suspended its operation until additional protections could be implemented.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The public disclosure does not establish how credentials were obtained, whether multifactor authentication was enabled, whether the VPN had an exploitable vulnerability, how long attackers had access, whether malware was used, or whether they gained administrative privileges. A suspected VPN path is not proof that a specific product flaw caused the incident.

Who was behind the attack?

Nidec’s notice refers to an “external criminal group” and does not publicly name a threat actor. SecurityWeek reported that both 8Base and Everest had listed Nidec on leak sites during the relevant period and said the company’s notice appeared to point toward Everest. That is a reported attribution based on leak-site activity, not a definitive public forensic identification by Nidec.

What did Nidec do in response?

Nidec said it and its group companies took several containment and follow-up measures:

  • Ran full scans of endpoints and reset passwords
  • Reviewed server access permissions
  • Suspended NPCV’s suspected VPN equipment pending additional protections
  • Consulted outside security specialists and lawyers
  • Continued security-system improvements and employee education
  • Reported the incident to Vietnamese authorities

Nidec also warned recipients to be alert for suspicious messages or links from people impersonating Nidec, its group companies, or the attackers.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should Nidec suppliers and customers watch for?

The disclosed file categories include invoices, purchase orders, contracts and business correspondence. Those records can provide convincing context for fraud attempts, even when no misuse has yet been identified. Suppliers and customers should treat unexpected requests that refer to Nidec-related business as unverified until checked through a trusted, previously established channel.

  • Verify changes to bank details, payment instructions or invoice recipients using a known phone number or contact—not details supplied in the message.
  • Be cautious with unexpected contract, purchase-order or document-sharing links, especially if the sender pressures you to act quickly.
  • Confirm unusual requests to disclose account credentials, reset access or share confidential files through an independent channel.
  • Report suspected impersonation to your organization’s security or finance team and preserve the message and headers where possible.

What remains unknown?

Nidec’s October 17, 2024 account said it had found no evidence of misuse of leaked information and assessed that the incident had not directly exposed information capable of causing economic secondary damage. Those are the company’s findings at the time of that notice, not a guarantee that downstream harm could never occur.

The public notice does not give a complete list of affected files or people, explain the original credential compromise, provide a definitive technical attribution, or establish whether the incident affected Nidec production or customer operations. It also does not support claims that a particular number of customers or employees had sensitive personal data stolen.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.