Sep. 15, 2026
We are writing to provide an update following our “Notice Regarding Unintentional Visibility of User Data“ published on June 16, 2026. In light of the matters described in that notice, we have since conducted a comprehensive investigation of the systems we manage to determine whether any similar issues occurred, including a review of how user data is stored and the access scope of such data. As a result of this investigation, we identified some systems in which, due to issues relating to system configuration, design, operation, or other factors, user data had been accessible, or may have been accessible, beyond the extent necessary for business purposes. Passwords and other authentication information were not included, and the user data was not accessible to the general public over the internet. Access to the user data was limited to users authorized to access our relevant systems. At this stage, we have not identified any misuse of the user data or other secondary harm resulting from these issues. We sincerely apologize for any inconvenience and concern this may have caused.
We will ensure the proper management of user data and take steps to prevent recurrence.
1. Overview of the Issues
An overview of the user data that was accessible, or may have been accessible, in connection with these issues is provided below.
Please note that the types of data vary depending on the user and the system concerned, and not all of the types of data listed in the table below were accessible with respect to every affected user. In addition, as some users use multiple systems, the numbers of affected registered users provided below include the same users in more than one of the following items.
| No. | Overview | Types of data | Number of affected registered users |
|---|---|---|---|
| 1 | A file containing user data posted on a portal site used by Komatsu Group companies, distributors, and others was accessible for viewing and downloading. | Name, email address, user ID, company name, parent company name, user type, account status (active or inactive), account creation date and time, the user or system that created the account, date and time of the most recent update, the user or system that made the most recent update, date and time of the most recent login, operating system used, browser information, and regional classification | 214,916 |
| 2 | In a system used internally for approval procedures relating to design changes and other matters, a function used in the application and approval process allowed user data to be searched and viewed beyond the scope necessary for specifying recipients. | Name, and company name | 29,621 |
| 3 | In a sales-related business system used by Komatsu, its distributors, and other relevant parties, a function relating to access authorization requests allowed users to search for and view user data belonging to other companies. | Name, email address, company name, department/division name, and job title | 86,015 |
| 4 | In a system used by distributors to report product quality information to Komatsu, a function for switching the department in charge allowed user data to be viewed beyond the scope necessary for reporting quality information. | Name, email address, company name, department/division name, and telephone number (only for some of the affected users) | 46,445 |
2. Our Actions
Upon identifying these issues, we implemented measures necessary in light of the circumstances of each system, including changing the relevant settings to restrict access, removing the relevant files from view, and limiting the scope of accessible data to that necessary for business purposes. As a result of these measures, in all of the relevant systems, the user data is no longer accessible beyond the extent necessary for business purposes in the manner identified in these issues.
In accordance with the Act on the Protection of Personal Information of Japan, we have taken all required measures, including reporting to the Personal Information Protection Commission of Japan.
3. Recurrence Prevention Measures
We take the matters identified in these issues seriously and will conduct a renewed review of the management of access rights for systems that handle user data, the methods used to store user data, the settings governing the scope within which user data can be searched and viewed, and the verification procedures followed in system operations.
In addition, we will strengthen our review and verification processes concerning the handling of user data at every stage of system design, development, and operation, and will implement the necessary system modifications and operational improvements to prevent a recurrence.
4. Contact for Inquiries
Komatsu Ltd.
E-mail address: JP00MB-privacy@global.komatsu
*The information may be subject to change without notice.