victim is an alias used by an as-yet unattributed threat actor associated with a claimed 2026 intrusion into Tokyo FM Broadcasting Co., LTD., a Japanese media organization. The actor publicly asserted that it had compromised the company’s private systems and exfiltrated a large volume of personal and technical records affecting listeners and employees. Reported stolen information included personal profile data, account-related identifiers, and internal employment-related information. Based on currently available facts, the activity is consistent with financially motivated cybercrime centered on unauthorized access and data theft. Attribution to any nation state, established intrusion set, or broader criminal program is not currently supported by high-confidence evidence. No corroborated information is available on additional aliases, sub-groups, tooling, or tradecraft beyond the claimed breach and data theft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.