← Incident database

komatsu-user-directory-exposure-2026 · Disclosed 2026-06-16

小松製作所: data exposure and authorization boundaries

Design, configuration and operational defects allowed authorized users to view personal information beyond the necessary scope. The first notice covered 139,302 people; further reviews found scopes of 214,916, 29,621, 86,015 and 46,445. Overlap prevents addition; the data was not publicly accessible on the internet.

Configuration / exposureImplementation

Outcome: Exposure / potential leak. Third-party theft unconfirmed.

Entry path and evidence

  • Reported fact

    Design, configuration and operational defects allowed authorized users to view personal information beyond the necessary scope.

    [s1]9月15日 §§1-3 / 6月16日 §§1-5
  • Reported fact

    The first notice covered 139,302 people; further reviews found scopes of 214,916, 29,621, 86,015 and 46,445. Overlap prevents addition; the data was not publicly accessible on the internet.

    [s1]9月15日 §§1-3 / 6月16日 §§1-5

Timeline

  1. Disclosure date established by the reviewed notice. [s1]

Reported response

  • Reported fact

    Permissions were changed and files hidden to stop unnecessary access.

    [s1][s2]9月15日 §§1-3 / 6月16日 §§1-5

Evidence relevant to prevention

Operational controls to inspect

Inspect the disclosed configuration, authorization or operational issue. Verify applicability and retain evidence of behavior after remediation.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The reviewed disclosures do not establish attacker use of AI.

The exact start date and overlap among affected user groups are unknown; additional scopes cannot be summed.

Sources

  1. [s1] 小松製作所 · Primary source

    小松製作所:事故に関する公表資料 ↗

    Reviewed 2026-10-09

  2. [s2] 小松製作所 · Primary source

    小松製作所:事故に関する公表資料 ↗

    Reviewed 2026-10-09