HackingStolen CredentialsCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSHEALTH_BASICMediumContained
KUBOTA NORTH AMERICA CORPORATION
bd_06cffe81691988e8 · schema v1 · pii pii-v1
Full breach record for KUBOTA NORTH AMERICA CORPORATION →Kubota North America Corporation notified Massachusetts residents of a data breach involving unauthorized access to HR network systems between March 16, 2026, and April 20, 2026. Files accessed contained employee PII, including SSNs, DOBs, driver's licenses, financial account info, and payment card data. Kubota secured the network and provided free identity monitoring via Kroll.
Massachusetts clock⏱ MA AG >30d5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_1198de85103a5d07New Hampshire State AGfiled 2026-06-30(29d gap)Verified
- bd_c1f97af719541b68Indiana State AGfiled 2026-06-30(29d gap)Verified
- bd_ebfa36b9b7bd0f75California State AGfiled 2026-06-30(29d gap)Candidate
- bd_50f85918d904e986Texas State AGfiled 2026-07-01(30d gap)Verified
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-1065-kubota-north-america-corporation/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 1, 2026
- Raw hash
- f9cef58fd9a29bfa3bc015b6d7e02a3678da5b317349bf9f035abae771f885bf
Reporting entity
- Name
- KUBOTA NORTH AMERICA CORPORATIONnorm: kubota north america
Victim entity
- Name
- KUBOTA NORTH AMERICA CORPORATIONnorm: kubota north america
Incident
- Discovered
- Apr 30, 2026
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 5 weeks(32 days from discovery to filing)
- Compliance flags
- MA AG >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.