Toshiba’s European Operations Hit by Hacker Group DarkSide Cyberattack

The News: A subsidiary of Toshiba’s European operations were the victim of a DarkSide cyberattack on May 4th, and reported publicly on May 14th. The company reported that as a result of the attack, the company shut down network connections between Europe and Japan to mitigate potential risk as the hack is being investigated. More at Cyberscoop.

Toshiba’s European Operations Hit by Hacker Group DarkSide Cyberattack

Analyst Take: The DarkSide cyberattack on Toshiba’s European operations appears thus far to be limited to the company’s European operations and focused on Toshiba Tec, which sells POS systems for retailers. There’s not yet been confirmation by the Toshiba subsidiary of the scope of the leaked information, and an investigation is still underway.

This is the second cyberattack in recent times aimed at Toshiba, following an earlier attack that happened in France. Early on Friday May 12th, DarkSide took responsibility for that attack and claimed to have accessed over 700 GB of data. The data compromised in the France attack included data around projects, human resources, passports and personal information of employees (including executive management), sales, and new business and trade information.

Why Japanese Companies are Attractive Targets for Threat Actors

Takashi Yoshikawa, a cybersecurity expert with Mitsui Bussan Secure Directions was interviewed about these recent attacks on Toshiba and noted that attacks on Japanese companies are at their highest ever. He also stated something that we’ve discussed at length here: the fact that with so many employees working from home and remotely accessing company systems, organizations are more vulnerable to cyberattacks.

Yoshikawa indicated that he believes Japanese companies are attractive targets for threat actors as a whole, because they don’t properly estimate the time and resources needed to put the right security protections and protocols in place, and when they are advised about that, they don’t tend to take the advice. Perhaps soon they will learn and adjust that mentality.

My colleague and fellow analyst here at Futurum Research and I covered the Toshiba DarkSide attack in the most recent episode of the Futurum Tech Webcast, as part of our Cybersecurity Shorts series. You can find the brief conversation here:

Or access the entire episode, which includes a number of timely insights on cybersecurity-related topics, here:

Disclaimer: The Futurum Tech Webcast is for information and entertainment purposes only. Over the course of this podcast, we may talk about companies that are publicly traded and we may even reference that fact and their equity share price, but please do not take anything that we say as a recommendation about what you should do with your investment dollars. We are not investment advisors and we do not ask that you treat us as such.

More Insights from Futurum Research:

Vodafone And Qualcomm Embark On Vision Quest For Open RAN Vendor Diversification And Swifter 5G Innovation

Plus Announces SPAC Deal To Take Self-Driving Truck Startup Public

Automation Anywhere Announces Early Access To Google Cloud-Powered Automation 360

Transcript:

Shelly Kramer: Speaking of governments, I wanted to wrap up the show with just a couple of quick highlights, and a nod to the fact that it’s not just the US Government that has issues with cybersecurity.

I saw earlier today that a subsidiary of Toshiba’s European operations were the victim of a cyber attack, perpetuated by DarkSide, our friends DarkSide, on May 4th. And, the attack appears to be limited to Toshiba’s European operations, and focused on part of the company called Toshiba Tec, which sells point-of-sale systems for retailers. Think lots of personally customer identification that goes through point-of-sale systems. There hasn’t been a confirmation yet of the scope of the leaked information, an investigation is still underway. This is the second attack in recent times aimed at Toshiba, an earlier one happened in France. DarkSide took responsibility for the France attack, and claimed to have accessed over 700 gigs of data, including data around projects, human resources, senior executives, passports, and personal information of employees, sales, new business and trade information. So, when you think about, this is an example of what we’re talking about when we say Government goes in to protect all of this data, because there’s so much data involved.

The thing that I thought was really interesting, coming out of the Toshiba attack, was that a cybersecurity expert that was interviewed about this said that, “Attacks on Japanese companies are at their highest ever. And, the Japanese are very attractive targets for threat actors as a whole because they don’t properly estimate that time and resources needed to put the right security protections and protocols in place.” I don’t think the Japanese are alone here, by the way.

Fred McClimans: No, I don’t.

Shelly Kramer: “And, when they are advised, what they need to do, they don’t tend to take the advice.” So, I thought that was really interesting on a number of fronts related to these conversations.

Author Information

Shelly Kramer is a serial entrepreneur with a technology-centric focus. She has worked alongside some of the world’s largest brands to embrace disruption and spur innovation, understand and address the realities of the connected customer, and help navigate the process of digital transformation.

Related Insights
Peraton's $117M Army Cyber Win: Trust Is the New Moat
August 19, 2026

Peraton’s $117M Army Cyber Win: Trust Is the New Moat

Peraton won a $117 million contract through 2031 to provide cybersecurity operations for the U.S. Army Regional Cyber Center–Europe, showcasing how long-term partnerships drive competitive advantage in defense contracting....
Peraton's $117M Army Recompete: A Cyber Partnership Blueprint
August 18, 2026

Peraton’s $117M Army Recompete: A Cyber Partnership Blueprint

Peraton secures $117M Army cyber contract through 2031, demonstrating how proven partnerships drive national security and recurring revenue for defense contractors....
Is the Rise of Agentic AI Threatening Cybersecurity Readiness?
August 15, 2026

Is the Rise of Agentic AI Threatening Cybersecurity Readiness?

Taiwan confirmed an autonomous AI cyber attack in July 2026. Tenable tracked seven incidents across three threat actors, signaling enterprises must urgently build defenses against offensive AI....
Cisco Q4 FY 2026 Earnings Point to Broader AI Infrastructure Demand
August 14, 2026

Cisco Q4 FY 2026 Earnings Point to Broader AI Infrastructure Demand

Futurum Research analyzes Cisco’s Q4 FY 2026 earnings, focusing on AI infrastructure orders, networking demand, security traction, and FY 2027 guidance....
Thales' H1 2026 Results Highlight Strategic Shifts in Cybersecurity Investments
August 14, 2026

Thales’ H1 2026 Results Highlight Strategic Shifts in Cybersecurity Investments

Thales' H1 2026 results reflect a $242B cybersecurity market forecast through 2029, with enterprises planning 5-15% budget increases and 74% showing strong vendor retention, signaling sustained momentum in data security...
SailPoint's Upcoming Earnings Call: What to Expect and Why It Matters
August 14, 2026

SailPoint’s Upcoming Earnings Call: What to Expect and Why It Matters

SailPoint's Q2 2027 earnings report comes as identity security demand strengthens, with the cybersecurity market forecast to reach $337.8B by 2029, reinforcing durable demand for its governance platform....

Book a Demo

Welcome

The vision behind everything in Futurum’s Custom Research practice is this: research should show you what is happening, what comes next, and what to do about it. It should be personal to each audience, easy for people to grasp, and structured so LLMs can reason over it accurately. And it should be fast and turnkey; you want answers now, not another project to carry for quarters.

Whether you are defining business, channel, or go-to-market strategy; evaluating vendors or justifying ROI; or commissioning research to fill an emerging market need, we have your back, with a program that answers your questions with the objectivity and credibility to drive real decisions.

To do it, we bring unmatched data to bear: Futurum research, surveys, and market projections; validated market feeds; ETR’s 15 years of insight from 10,000 technology decision-makers; G2’s buyer and user data; and what our analysts hear every day. Add leading primary collection, from AI-moderated voice interviews to surveys and analyst-led interviews, all turnkey, and every project comes out credible, nuanced, and actionable.

And we don’t just drop the results in your lap. For internal work, we provide analyst-led sessions, interactive dashboards, and a range of formats. For market-facing work, Futurum delivers turnkey activation and amplification that actually gets seen, by people and by LLMs, through our media and share of voice. This is research that moves decisions and markets.

We will meet you wherever you are, from a fast-turn brief to a multi-year program, and shape the work to your goals, timeline, and budget. The right program for your moment.

If any of this is useful, I would love to talk.

Benjamin Brown, VP Custom Research, Futurum Research

Benjamin Brown

VP, Custom Research · The Futurum Group

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.