Kubota North America disclosed that an unidentified threat actor gained unauthorized access to parts of its internal network from March 16 to April 20, 2026, later determining that human resources and employee-related files had been accessed. The company said the exposed information included names, Social Security numbers, dates of birth, taxpayer identification numbers, driver’s license or other government ID details, direct-deposit bank account information, corporate payment card data, and some benefits enrollment and limited claims information affecting employees and their dependents.
Kubota said it secured affected systems, engaged external cybersecurity experts, notified law enforcement, and began sending individualized notices to affected people on June 30 while offering complimentary identity protection and credit monitoring through Kroll. Reporting on the incident differed on operational impact, with one account saying routine operations in the North American division were disrupted while another said no operational disruption was reported; no threat actor had publicly claimed responsibility at the time of disclosure.

See attribution, scope, and your downstream exposure.
7 events from the most recent confirmed update back to the earliest known activity.
Following discovery of the SLA incident, IBM revoked access to the affected cloud environment. SLA began notifying impacted individuals and investigating with IBM, Singapore government agencies, external cybersecurity experts, law enforcement, and the Personal Data Protection Commission.
The Singapore Land Authority disclosed a cybersecurity breach involving unauthorized access to an IBM-managed cloud environment used for development and testing. SLA said the affected environment was separate from live operational systems and that core land systems and records were not impacted.
Kubota began sending individualized email notifications to affected people on June 30, 2026. The company also offered Kroll identity protection services to those impacted.
On April 30, 2026, Kubota determined that human resources files had been accessed during the intrusion. The exposed information included sensitive personal and financial data such as Social Security numbers, dates of birth, taxpayer IDs, driver's license details, direct deposit information, and corporate card data.
Kubota said the unauthorized access to its network systems continued until April 20, 2026. The company later secured affected systems and investigated the incident with external cybersecurity experts.
Kubota North America said an unidentified threat actor gained unauthorized access to some of its internal network systems beginning on March 16, 2026. The intrusion ultimately affected files containing employee and dependent personal information.
The Singapore Land Authority said a dataset created in 1998 for development and testing, which was intended to contain mock and anonymized data, instead contained real names, NRIC numbers, and former property addresses. Preliminary findings said about 70,000 individuals were affected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourceteiss.co.uk
Open sourcecyberveille.ch
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.