2026 Mazda Motor — 692 individuals (Thailand warehouse platform; employees & partners only)
Data compromised
Names, emails, user IDs, company names, business partner data (employees & partners; no customer data per Mazda)
Technical writeup
Mazda Motor Corporation disclosed unauthorized external access to a warehouse-management platform used for parts procured from Thailand—recently confirmed in March 2026 regulatory materials and press (Japanese disclosure PDF referenced in reporting). Attackers exploited vulnerabilities in that system; Mazda stated the environment did not contain customer data. Investigation identified 692 potentially exposed records tied to employees and business partners: user IDs, full names, email addresses, company names, and business partner IDs. The company reported to Japan's Personal Information Protection Commission, patched, reduced internet exposure, and tightened access controls. Mazda stated no confirmed ransomware or operational disruption; prior Clop leak-site claims were described by media as not confirmed as the same incident.
Root cause
Exploitation of vulnerabilities in warehouse-management platform; unauthorized external access