← Kubota

2026 Kubota North America — month-long network intrusion; employee HR data exposed (Mar–Apr)

2026 2.2K records affected Share on X

Data compromised

Per Kubota notice: names (including dependents), Social Security numbers, dates of birth, taxpayer IDs, driver's license or government ID numbers, direct-deposit bank account information, corporate payment card information, and benefits enrollment/limited claims data—varies by individual

Technical writeup

Kubota North America Corporation disclosed that an unauthorized third party accessed certain network systems for more than a month between March 16 and April 20, 2026. After forensic review Kubota determined the actor accessed files containing personal information for employees and their dependents. Exposed categories include names, Social Security numbers, dates of birth, taxpayer IDs, government ID numbers, direct-deposit bank details, corporate payment card information, and benefits enrollment and limited claims data, varying by person. Kubota began emailing personalized notification letters June 30, 2026 offering Kroll identity protection and advising recipients to monitor healthcare statements and bank accounts. State filings cited at least 2,237 Texas residents at catalog time; Kubota had not published a global victim total and no ransomware group claimed responsibility. Kubota states it implemented additional security measures and did not report operational disruptions.

Root cause

Unauthorized access to Kubota North America Corporation network systems between March 16 and April 20, 2026; investigation determined personal files for employees and dependents were accessed

References