Dentsu, a leading Japanese advertising and public relations firm, confirmed that its U.S.-based subsidiary Merkle experienced a cybersecurity incident resulting in the exposure of sensitive staff and client data. The breach prompted the company to take certain systems offline as a precaution and initiate incident response protocols, including engaging third-party cyber experts and notifying law enforcement. Dentsu stated that the incident did not impact its network systems in Japan and that the financial impact remains undetermined at this time.
The investigation revealed that files containing information related to clients, suppliers, and both current and former employees were accessed and stolen. Exposed data reportedly includes bank and payroll details, salary information, National Insurance numbers, and personal contact details. Impacted individuals are being notified, and Dentsu has reported the incident to relevant authorities in affected countries as required by law. Merkle, which operates globally and serves high-profile clients, is working to restore normal operations and assess the full scope of the breach.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
Subsequent reporting said Dentsu warned staff following the Merkle data breach and provided additional detail on the impact to employees and clients. These reports expanded public understanding of the breach's scope but did not indicate a separate incident.
Dentsu published an official cyber incident statement acknowledging the breach affecting Merkle and related international operations. The company said it was investigating the incident and taking response measures.
Dentsu disclosed that its U.S. subsidiary Merkle experienced a cyber incident that resulted in unauthorized access to data. Reports said the exposed information included employee data and some client-related information.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
5 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcego.theregister.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourcegroup.dentsu.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.