nidek-website-2026 · Disclosed 2026-07-24
NIDEK medical devices: website software vulnerability exploited
NIDEK reported exploitation of website software. Member and inquiry data may have been accessed; the cited FAQ does not confirm external disclosure.
Outcome: Confirmed breach
Entry path and evidence
- Reported fact
The FAQ dates initial access to around 01:00 JST on July 20 and detection to July 24, and identifies a website-software vulnerability.
[s2]FAQ Q1 / Q3 / Q14 - Reported fact
Member and inquiry information was potentially affected; approximately 28,000 members is a potential-impact figure, not confirmed exfiltration.
[s2]FAQ Q2 / Q7 / Q17
Timeline
Incident disclosed. [s1]
Reported response
- Reported fact
NIDEK patched on detection and engaged specialists. Historical inquiries were removed from the website but retained separately for investigation and safeguards.
[s2]FAQ Q4 / Q10 / Q14
Evidence relevant to prevention
Insufficient evidence
Inspect deployed versions, update records, and inquiry-data retention; unknown pre-intrusion patch timing prevents a neglect finding.
Editorial assessment; not a determination of liability. [s2]
Unknowns and AI involvement
The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence.
Product, CVE, patch timing, and confirmed leakage scope are unspecified; NIDEK is distinct from motor manufacturer NIDEC.
Sources
[s1] NIDEK · Primary source
当社Webサイトへの不正アクセスに関するお知らせ ↗Published 2026-07-24 · Reviewed 2026-10-02
[s2] NIDEK · Primary source
FAQ Regarding Unauthorized Access to Our Website ↗Published 2026-08-19 · Reviewed 2026-10-02