Kubota says hackers roamed its network for over a month before detection

Kubota North America says attackers had access to its network systems for more than a month. From March 16 to April 20, the threat actor pulled files containing personal information on employees and their dependents.

Kubota’s a Japanese industrial giant — tractors, construction equipment, utility vehicles. They operate in 120 countries with 52,000 employees and $20 billion in annual revenue. The North American division handles the tractors and mowers.

What got taken? Full names, Social Security numbers, dates of birth, taxpayer IDs, driver’s license numbers, direct deposit bank info, corporate payment card data, and benefits enrollment details. All for employees and their dependents. The specific data varies per person.

Kubota started sending personalized notifications on June 30. They’re offering Kroll identity protection. The letters tell people to watch healthcare statements and bank accounts closely — report anything suspicious immediately.

The company says it has added security measures to prevent this from happening again. No ransomware gang has claimed responsibility. No word on operational disruptions either.

BleepingComputer reached out to Kubota for more details on who did it and how. No response yet.