← Incident database

nidek-website-2026 · Disclosed 2026-07-24

NIDEK medical devices: website software vulnerability exploited

NIDEK reported exploitation of website software. Member and inquiry data may have been accessed; the cited FAQ does not confirm external disclosure.

Cause unresolved / undisclosed

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    The FAQ dates initial access to around 01:00 JST on July 20 and detection to July 24, and identifies a website-software vulnerability.

    [s2]FAQ Q1 / Q3 / Q14
  • Reported fact

    Member and inquiry information was potentially affected; approximately 28,000 members is a potential-impact figure, not confirmed exfiltration.

    [s2]FAQ Q2 / Q7 / Q17

Timeline

  1. Incident disclosed. [s1]

Reported response

  • Reported fact

    NIDEK patched on detection and engaged specialists. Historical inquiries were removed from the website but retained separately for investigation and safeguards.

    [s2]FAQ Q4 / Q10 / Q14

Evidence relevant to prevention

Insufficient evidence

Inspect deployed versions, update records, and inquiry-data retention; unknown pre-intrusion patch timing prevents a neglect finding.

Editorial assessment; not a determination of liability. [s2]

Unknowns and AI involvement

AI involvementUnknown

The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence.

Product, CVE, patch timing, and confirmed leakage scope are unspecified; NIDEK is distinct from motor manufacturer NIDEC.

Sources

  1. [s1] NIDEK · Primary source

    当社Webサイトへの不正アクセスに関するお知らせ ↗

    Published 2026-07-24 · Reviewed 2026-10-02

  2. [s2] NIDEK · Primary source

    FAQ Regarding Unauthorized Access to Our Website ↗

    Published 2026-08-19 · Reviewed 2026-10-02