Komatsu America Corp.
bd_fe1aacb9ca143992 · schema v1 · pii pii-v1
Full breach record for Komatsu America Corp. →Komatsu America Corp. notified the New Hampshire Attorney General of a cybersecurity incident discovered on September 22, 2021. An unauthorized external actor used stolen credentials to access an employee's email account between September 20 and 22, 2021. The actor bypassed MFA and created malicious rules to hide inbound messages. While no evidence suggested data was accessed, the account contained PII, SSNs, and financial info. Two NH residents were notified on December 6, 2021, and offered 12 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 20, 2021
Begins
Sep 22, 2021
Discovered
Dec 6, 2021
Filed
vs. sector median
on median
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Maine State AGbd_076fbb8f08f92a742021-12-06Candidate
- Massachusetts State AGbd_d8b45c2be2cb29482021-12-07 · +1dVerified
Filing propagation · 3 filings · 3 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.