• We're currently having issues with our e-mail system. Anything requiring e-mail validation (2FA, forgotten passwords, etc.) requires to be changed manually at the moment. Please reach out via the Contact Us form if you require any assistance.

Other NicoNico Cyberattack and Outage

Vector

Passionate Fan
Mar 6, 2022
157
NicoNico has been down since June 8th, attempting to recover from a cyberattack involving ransomware.


Report and apology regarding cyber attacks on our services

<Dwango Press Release: Published June 14th (Friday) at 3pm>

As announced in Niconico Info dated June 8, 2024, Dwango Co., Ltd. (Headquarters: Chuo-ku, Tokyo; President and CEO: Takeshi Natsuno) has been unable to use the "Nico Nico" service operated by the company since the early morning of June 8. It has been confirmed that this outage is the result of a large-scale cyber attack, including ransomware. We have temporarily suspended use of the service and are currently investigating and responding to understand the full extent of the damage and restore operations.

After confirming the cyber attack, we immediately took emergency measures, such as shutting down the relevant servers, and set up a task force to fully investigate the damage, determine the cause, and restore the system. We would like to report the findings of our investigation to date and our future response as follows.

We sincerely apologize to our users and all concerned parties for the inconvenience and concern caused.

<Background to the response>
At around 3:30 AM on June 8th, a malfunction occurred that prevented all of our web services, including our "Nico Nico" and "N Yobikou" services, from functioning normally. After an investigation, it was confirmed that the malfunction was caused by a cyber attack, including ransomware, at around 8 AM that same day. A task force was set up on the same day, and in order to prevent the damage from spreading, we immediately cut off communications between servers in the data center provided by our group company and shut down the servers, temporarily suspending the provision of our web services. In addition, as it was discovered that the attack had also extended to our internal network, we suspended the use of some of our internal business systems and prohibited access to the internal network.
As of June 14th, we are currently assessing the extent of the damage and formulating recovery procedures, aiming for a gradual recovery.
 

Luxie

Kagamine Rin and Len cover artist
Aug 3, 2022
60
Eastern USA
I would also like to note that there is a temporary accommodation called NicoNico Douga (Re:Tentative) (「ニコニコ動画(Re:仮)」Pretty much, they have a service that has a limited amount of videos that are mostly from 2007.

(MACHINE) TRANSLATION: "Today, we released a new version, "Nico Nico Douga (Re:tentative)". Only a limited number of videos are available, with popular videos from 2007 currently available, and more will be added in the future. While the service is suspended, it will be available without an account, although it will be available with minimal functionality, just like when the service first started."


(MACHINE) TRANSLATION: "While “Niconico” is suspended, the first service will be a new version of “Niconico Douga (Re: Kari)” that will be released at 3:00 p.m. on June 14, 2024. Our development team spontaneously created it in a short period of 3 days, and it is a video community site with only basic functions such as video viewing and commenting, just like NicoNico's first service (2006). In consideration of the service load, only a selected number of videos posted on Niconico Douga are available for viewing. The lineup mainly consists of popular videos from 2007, and you can watch them for free without an account."

While I am glad that the staff are doing what they can, it's also incredibly worrying for content creaters, fans, and staff. I hope that NND recovers in good time. And I also feel sorry for all of the people who are fans of or contributed to NND as well, as I'm sure that this is scary for at least some of them.
 

MagicalMiku

♡Miku♡
Apr 13, 2018
1,783
Sapporo
there are legendary Vocaloid videos available on NicoNico Re:Tentative, like

on a positive side, it's good all videos are safe and they stopped the attack before it could have become much worse. and at least the attack happened during a less "busy" period. probably it'll take a bit longer than one month (I think 2 months for a full recovery), but yes, such things can happen and are a good reminder that is always good to save favorite videos on own pc, because NicoNico is really part of Vocaloid history from the beginning and I look forward to its fully recovery:miku_lili::luka_lili::len_smile_lili::rin_smile_lIlI::meiko_lili::kaito_smile_lili:
 

Vector

Passionate Fan
Mar 6, 2022
157
They remarked on it during the Final Fantasy XIV "Letter from the Producer" broadcast, as they usually stream it on NND as well as YouTube and Twitch. (And FFXIV has also been under DDoS for a few weeks now.)

Definitely a major part of Vocaloid, and I'm glad they haven't had any data loss.
 

pico

robot enjoyer
Sep 10, 2020
556
Just an important distinction I think some have missed— this attack was *not* an attack that exclusively targeted niconico services. This attack impacted effectively ALL Kadokawa servers and services. So if you have accounts on Kadokawa marketplaces, keep an eye on your email in case more information arises. As of now they haven’t updated again on the extent of the breach (I.e. they don’t know what, if any, data was stolen) and when it is discovered it will likely be communicated to affected users via email, so be aware.
 

MagicalMiku

♡Miku♡
Apr 13, 2018
1,783
Sapporo
if it was a ransomware without any other malware, then it is likely that the attack was made only to block all data on the servers and then ask money to unblock it (I made it simple, but it's basically why ransomware are made). We don't know, but yes, it's possible that in any case all login passwords, not only niconico but all other Kadokawa services, will be reset :una_lili:
 

pico

robot enjoyer
Sep 10, 2020
556
if it was a ransomware without any other malware, then it is likely that the attack was made only to block all data on the servers and then ask money to unblock it (I made it simple, but it's basically why ransomware are made). We don't know, but yes, it's possible that in any case all login passwords, not only niconico but all other Kadokawa services, will be reset :una_lili:
kai-you.net/article/89946

Everyone should be very careful not to assume attacks like this are “just ransomware” until full reports about attack scale are shared. Especially when Kadokawa stated from the beginning that the attackers had network access. When cybercrime happens the rule of thumb should always be to assume you are compromised for your own safety until there is confirmation otherwise.

The attack was performed by Russian group BlackSuit. They claim 1.5TB of data was stolen, which they will release if the ransom is not paid by July 1st.

Thankfully for users, it seems that the most personal data is not part of the data collected. But “emails, data usage, links opened” are.

It will be interesting to see what happens on July 1st. Personally missing NND a lot right now. I can only assume kdkw will cut their losses. If this releases, perhaps some of the corporation’s more underhanded ventures will be in the spotlight again i.e. 4chan investment.
 

MagicalMiku

♡Miku♡
Apr 13, 2018
1,783
Sapporo
mm.. I suspected there was more about it, and the 1.5TB of data is more of a "bargaining chip" for asking money. I've also read that the group is willing to provide assistance in terms of security, which might sound a bit strange, but these groups do these kind of acts for money, it's their business, and they're ok with that if the money comes from the ransomware, the deadline of data release or a contract for future security assistance. Kadokawa is a big company, so there is not problem for that.

it's a big reminder to always choose a different password for each service you sign up, these things happen daily, and there will be surely a password reset for all accounts (and maybe also some user history and comments settings change), and the good thing is that the whole network of niconico will be stronger after all of this:una_lili:
 
Last edited:
  • Like
Reactions: Blue Of Mind

pico

robot enjoyer
Sep 10, 2020
556
Has Kadokawa stated they are going to pay the ransom? I would be surprised if they opt to pay the ransom.
 

MagicalMiku

♡Miku♡
Apr 13, 2018
1,783
Sapporo
I've read that Kadokawa first wanted to pay a portion of what asked for the ransom, but then there is this whole 1.5TB of data and the offer of assistance in terms of security. We don't know how much important or not is that data for the company itself (think of future company plans, employees profiles, etc..), but in my opinion, they'll have a kind of agreement with that group: if the group asked 100 and they first wanted to pay 10, then probably they'll pay 40 with agreement on assistance on building a stronger network. the weakest point was indeed the fact that all network sites and companies were linked together, that's not good. but it's good they can spend this time making it better and better :una_lili:
 

MagicalMiku

♡Miku♡
Apr 13, 2018
1,783
Sapporo
a little update about it:
Kadokawa confirmed that information on contracts with business partners as well as personal information of all employees of its subsidiary, Dwango, had been leaked to outside parties.
from The Asahi Shimbun:

from the article, it seems like that the 1.5TB of data stolen wasn't about company projects and user details, but contracts with business partners (in this case some projects can be assumed, but not confirmed) and employees information, so it makes sense they didn't want to pay the full amount of what asked. Hoping for a full recovery during this month, but I know it can take some time, I miss niconico:kaito_lili:
 
Last edited:

MagicalMiku

♡Miku♡
Apr 13, 2018
1,783
Sapporo
some updates about niconico recovery(●'◡'●)✨
[Notice] Starting at 12:00 on Thursday, July 25th, the videos available to watch on Niconico Video will be switched to "Popular Videos of 2017."
Thank you for using Nico Nico Manga.
Currently, new series launches and episode updates have stagnated since maintenance, and we deeply apologize for the inconvenience caused to everyone who has been looking forward to the release of manga.
The songs that can be played on the "Vocal Collection App/Simple Version" have been changed to popular songs from 2018
You can listen to songs by clicking "Find" at the bottom of the home screen.
You can enjoy many famous songs which has been played over 10 million times. Have a look and find your favorite song!
[Niconico recovery status as of 7/12] We apologize for the inconvenience and concern caused by the suspension of Niconico services due to the effects of a cyber attack. We would like to inform you of the current recovery status.

-Recovery is progressing smoothly, and we will be able to inform you of the expected recovery time soon.
-All data necessary for Niconico service recovery was safe (videos, comments, billing history, etc.)
-While proceeding with system recovery, we are identifying the steps necessary to resume service provision (overall operation checks, performance tests, security audits, etc.)
-We have provisionally released "Niconico Plaza," an experimental mini-service that was originally created in-house, from today.
 

MagicalMiku

♡Miku♡
Apr 13, 2018
1,783
Sapporo
very very good news!!(^∀^●)ノシ August 5th niconico will be back!!!!(。・∀・)ノ゙✨✨🎈🎉
Niconico official program "Monthly Niconico Info" (#月ニコ) issue 34 will be broadcast on Niconico Live Broadcast (Re:tentative) from 8:00 pm on Tuesday, July 30th!
-Niconico Douga resumes on Monday, August 5th! And to a new version!!
-Compensation for service interruption
-Other Niconico recovery plans
-The content will be different from usual
-The schedule is subject to change

~ Niconico Video will resume on August 5th with a new version ~ Niconico's recovery status and compensation for the service interruption

Thank you for using Niconico. Due to the cyber attack on a server in the KADOKAWA Group's data center that was discovered on Saturday, June 8th, all Niconico services have been unavailable. We deeply apologize for the great inconvenience and concern caused to our users and all related parties. Niconico management is working hard to restore the system, and has decided that multiple Niconico services, including Niconico Douga, will resume on Monday, August 5th, 2024. We would like to report the details of the resumption, as well as the compensation measures for the service suspension, as follows.

■ Resumption of Niconico services
The following services will resume on August 5th. When Niconico Douga resumes, Niconico will be a new version. User live broadcasts and Niconico Channel are scheduled to resume one after another during August. As a result, the currently offered temporary services "Niconico Douga (Re:provisional)", "Niconico Live Broadcast (Re:provisional)", "Niconico Commons (Re:provisional)", "Niconico Plaza (Re:provisional)", and "Niconico Live Commentary (Re:provisional)" will cease operation. Details on the restoration of each service will be announced on August 1st, and the names of the new versions will be announced on August 5th.

■Services to resume on August 5th (functions available in parentheses)
- Niconico Video (videos can be posted and viewed, and comments can be posted)
- Niconico Live Broadcast (official programs can be viewed and comments can be posted)
- Niconico Encyclopedia (articles can be viewed, created, and edited, and message boards can be viewed and responses can be posted)
- Niconico Seiga
- Niconico Commons
- Niconico 3D
- Niconico Q
- Creator Incentive Program
* Niconico Video will resume on PC/smartphone browsers, and Niconico Live Broadcast on PC. iOS/Android app versions of both services are scheduled to be available from early to mid-August. * As the Niconico system is being rebuilt into a new, safe environment, emergency maintenance may be performed as necessary for the time being after the service resumes in order to ensure stable operation. * "Paid Broadcasting: Niconico Live Broadcasting (Re: Provisional)" will continue until Niconico Live Broadcasting supports official paid broadcasting. * Niconico Seiga is scheduled to be restored from a backup around 10:30 on May 23rd. *Services that have already resumed: Niconico Manga, NicoFT

■Services and features to be resumed in August
- Niconico Channel: Scheduled for mid to late August (※1)
- User live broadcasts: Scheduled for early August
- VocaColle (iOS/Android app): Scheduled for mid-August
- Niconico ads, gifts: Scheduled for mid-August
- Niconico News: Scheduled for early August (※2)
- New followers (new feature replacing Nicorepo): Scheduled for late August
- Premium membership enrollment and withdrawal: Scheduled to resume for each payment method from mid-August
- N Preparatory School: Some features for free members and some features for schools will resume: Scheduled for early August ※1) Niconico Channel+ resumed service on June 28, and the login function with Niconico accounts is scheduled to be restored in mid to late August. ※2) Niconico News resumed news article viewing on July 11, and comments posting will be possible from early August.

■Services that will not resume in the new version
- Niconico Community
*Due to the loss of data and systems necessary for recovery, Niconico Community has been forced to abandon the resumption of service. We will make a separate announcement.

■Security measures to prevent recurrence
As previously reported, when we resumed our services, we suspended the use of affected devices and devices that may have been affected, reset various accounts, strengthened the security of our internal network communications, and reviewed our management policies. In addition, we have received support from an external major security specialist company and are rebuilding the Niconico system in a new environment and taking various measures to strengthen security.
We are currently working to confirm the leaked information with the support of an external major security specialist company, but this process is taking time and the confirmation has not yet been completed. We will report again as soon as more accurate information is available.

■Compensation for service interruption
The compensation details announced in the June 27 press release for Niconico premium members, Niconico Channel/Niconico Channel+, Creator Incentive Program, N Preparatory School, and Dwango Ticket users have been finalized. In addition, the compensation period will be extended from the originally scheduled June and July to August.

We would like to once again deeply apologize to our users for the inconvenience and concern caused. Niconico management will continue to do our utmost to restore service as quickly as possible, and will take this incident seriously, further strengthening our information security system and working to prevent recurrence. We hope you will continue to support Niconico.
 
Last edited:

39dearMIKU

No Miku, no life.
Apr 8, 2018
377
Germany
www.youtube.com
First time I have been back on the website...
I always thought the website was honestly kinda bad, but now nothing works?
Is this still being built up or on my end? If I go to the homepage, rankings, recommended videos, everything says "failed to load" (in Japanese). If I click on "videos", it loads endlessly.
I reset my password as it was recommended anyway, thought maybe for protection it only works if logged in now, still nothing.
Tried it with VPN off, tried it with VPN on as always "closeby server", tried it with being connected to a Japanese server... no change.
So, not sure, how it is "back", at least for me, nothing on the website works (and it has been "back" for 5 days now).
 

Users Who Are Viewing This Thread (Users: 0, Guests: 0)