Crew claims 4.1 TB haul from Japanese pharma giant Rohto

A Japanese drug and cosmetics maker found an intruder in its online store days before an extortion crew claimed a multi-terabyte theft.

MedRisk Staff
By
2 Min Read

Rohto Pharmaceutical says it detected suspicious activity inside the system that runs its mail-order and online shopping business on September 10, and an extortion actor moved fast to claim the theft.

Four days later, someone using the handle sta6 took credit for roughly 4.1 TB of data, saying the haul included about 3.95 million Salesforce customer records and some 850,000 recorded customer service calls. Rohto has described the event as a possible incident linked to its e-commerce infrastructure. It has not confirmed the volume, named the systems involved, or verified that the files are real.

The company is a major Japanese healthcare and cosmetics manufacturer, and its consumer health lines sit close to regulated medicine. Order histories and call recordings at a business like this often carry names, addresses, contact details, purchase patterns that hint at health conditions, and payment data. That combination is worth more to extortion crews than an ordinary retail haul.

The episode echoes the pattern that has dogged Salesforce customers all year, where stolen CRM exports and customer support archives surface in bulk. For pharmacy, clinic, and life-sciences teams, the storefront and contact center are frequently softer than the clinical network, and they rarely sit under the same monitoring.

Rohto has not said whether it received a demand or involved regulators.

Share This Article