Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Analyze » Keio University Global Research Institute (KGRI) » KGR1767786033

Incident Score: Analysis & Impact (KGR1767786033)

The details regarding individual company incidents & reports gives you full view from every side.

Rankiteo Score Impact Analysis

Rankiteo Incident Impact-104
Company Score Before Incident770 / 1000
Company Score After Incident666 / 1000
INCIDENT NUMBERKGR1767786033
Type of Cyber IncidentBreach
ATTACK VECTORZero-day attack
DATA EXPOSEDEmail addresses, password hashes, plaintext...
INCIDENT DATE25/11/2025
STATUSOngoing

Key Highlights From The Incident Analysis

  • Timeline of Keio University Global Research Institute (KGRI)'s Breach and lateral movement inside company's environment.
  • Overview of affected data sets, including SSNs and PHI, and why they materially increase incident severity.
  • How Rankiteo’s incident engine converts technical details into a normalized incident score.
  • How this cyber incident impacts Keio University Global Research Institute (KGRI) Rankiteo cyber scoring and cyber rating.
  • Rankiteo’s MITRE ATT&CK correlation analysis for this incident, with associated confidence level.

Full Incident Analysis Transcript

In this Rankiteo incident briefing, we review the Keio University Global Research Institute (KGRI) breach identified under incident ID KGR1767786033.

The analysis begins with a detailed overview of Keio University Global Research Institute (KGRI)'s information like the linkedin page: https://www.linkedin.com/company/kgri, the number of followers: 196, the industry type: Higher Education and the number of employees: 15 employees

After the initial compromise, the video explains how Rankiteo's incident engine converts technical details into a normalized incident score. The incident score before the incident was 770 and after the incident was 666 with a difference of -104 which is could be a good indicator of the severity and impact of the incident.

In the next step of the video, we will analyze in more details the incident and the impact it had on Keio University Global Research Institute (KGRI) and their customers.

On 23 December 2025, Keio University Shonan Fujisawa Campus (SFC) disclosed Data Breach issues under the banner "Unauthorized Access and Data Compromise at Keio University SFC-CNS Email Service".

Unauthorized access from outside the university led to the compromise of user email addresses and passwords associated with the Shonan Fujisawa Campus (SFC) SFC-CNS email service.

The disruption is felt across the environment, affecting SFC-CNS email service, spam quarantine server, directory server, and exposing Email addresses, password hashes, plaintext email passwords, Wi-Fi passwords, full names, ID numbers, forwarding email addresses, and spam quarantine emails, with nearly 6,447 accounts (directory server) + 222,508 emails (quarantine server) records at risk.

In response, teams activated the incident response plan, moved swiftly to contain the threat with measures like Blocked entry point, mandatory password resets, and began remediation that includes Investigation into the zero-day vulnerability, enhanced monitoring, and stakeholders are being briefed through Public disclosure, advisories to affected users.

The case underscores how Ongoing, and recommending next steps like Change compromised passwords for other services, exercise caution with suspicious emails, and monitor for secondary harm, with advisories going out to stakeholders covering Advisories issued to affected users regarding password resets and phishing risks.

Finally, we try to match the incident with the MITRE ATT&CK framework to see if there is any correlation between the incident and the MITRE ATT&CK framework.

The MITRE ATT&CK framework is a knowledge base of techniques and sub-techniques that are used to describe the tactics and procedures of cyber adversaries. It is a powerful tool for understanding the threat landscape and for developing effective defense strategies.

MITRE ATT&CK® Correlation Analysis

Rankiteo's analysis has identified several MITRE ATT&CK tactics and techniques associated with this incident, each with varying levels of confidence based on available evidence. Under the Initial Access tactic, the analysis identified Exploit Public-Facing Application (T1190) with high confidence (90%), supported by evidence indicating exploited via a zero-day vulnerability in its spam quarantine server software. Under the Credential Access tactic, the analysis identified OS Credential Dumping (T1003) with moderate to high confidence (80%), supported by evidence indicating directory server...stores user credentials and personal information and Credentials from Password Stores (T1555) with moderate to high confidence (80%), supported by evidence indicating hashed account login passwords, plaintext email passwords, Wi-Fi passwords. Under the Collection tactic, the analysis identified Data from Local System (T1005) with high confidence (90%), supported by evidence indicating exposed data includes email addresses, passwords, full names, ID numbers and Email Collection (T1114) with moderate to high confidence (80%), supported by evidence indicating spam quarantine server may have also leaked up to 222,508 messages. Under the Exfiltration tactic, the analysis identified Exfiltration Over C2 Channel (T1041) with moderate to high confidence (70%), supported by evidence indicating data breach affecting 6,447 accounts, including PII and passwords. Under the Defense Evasion tactic, the analysis identified Exploitation for Defense Evasion (T1211) with moderate to high confidence (80%), supported by evidence indicating zero-day vulnerability in its spam quarantine server software. Under the Impact tactic, the analysis identified Data Destruction (T1485) with lower confidence (30%), supported by evidence indicating no secondary misuse of compromised data has been confirmed to date. These correlations help security teams understand the attack chain and develop appropriate defensive measures based on the observed tactics and techniques.

Initial Access
Exploit Public-Facing Application (90%)
Credential Access
OS Credential Dumping (80%)
Credentials from Password Stores (80%)
Collection
Data from Local System (90%)
Email Collection (80%)
Exfiltration
Exfiltration Over C2 Channel (70%)
Defense Evasion
Exploitation for Defense Evasion (80%)
Impact
Data Destruction (30%)

Sources & References