Mazda Motor Corp.TSE: 7261

Apology and Notification Concerning Potential Incident of Personal Information Exposure Due to Unauthorized Access

· Issued by Mazda Motor Corp.

March 19, 2026 Mazda Motor Corporation

Apology and Notification Concerning Potential Incident of Personal Information Exposure Due to Unauthorized Access

Mazda Motor Corporation has identified traces of unauthorized external access to a management system used for warehouse operations related to parts procured from Thailand. Following this discovery, the Company promptly reported the matter to the Personal Information Protection Commission - an external bureau of the Japanese Cabinet Office - and implemented appropriate security measures and conducted an investigation in cooperation with an external specialist organization.

As a result of the investigation, it has been determined that there is a possibility that a portion of the personal information of the employees of the Company, its group companies, as well as business partners may have been exposed. Please note that no personal information relating to customers is stored in the system in question, and therefore there is no possibility that such information was affected.

To prevent recurrence, Mazda will continue to strengthen its information security framework, including enhanced monitoring of external access and strengthened communication controls.

We sincerely apologize for the significant inconvenience and concern caused by this incident.

  • Overview

    In mid-December 2025, it was discovered that information managed by the Company may have been exposed due to unauthorized access to the management system used for warehouse operations involving parts procured from Thailand. The internal investigation conducted in cooperation with an external specialist organization confirmed that security vulnerabilities in the system were exploited, resulting in unauthorized access to a portion of the information stored in the system.

  • Categories of Personal Data That May Have been Exposed

    The following personal information of employees of the Company and its group companies, as well as business partners, may have been affected (692 records):

    • User IDs issued by the Company

    • Name

    • Email address

    • Company name

    • Business partner IDs

  • Cause

    The cause of this incident was determined to be unauthorized access by a third party through the exploitation of security vulnerabilities in the system used for the Company's business operations.

    Consequently, there is a possibility that some of the information stored in the system may have been exposed.

  • Possibility of Secondary Damage

    Currently, no secondary harm has been confirmed. However, there is a possibility that the exposed personal information could be misused in the future, such as for phishing scams or spam emails. If you receive any suspicious communications, please exercise caution.

  • The Company's Response

    Upon recognizing this incident, the Company promptly reported the matter to the Personal Information Protection Commission and implemented appropriate security measures and conducted an investigation in cooperation with an external specialist organization.

    Based on the investigation results, the Company has revised the system to minimize Internet communication in order to prevent unauthorized external access. In addition, it is restricting access sources, promptly applying security patches, and strengthening access monitoring to establish a framework for the early detection of suspicious activities.

    Mazda will continue to work toward further strengthening information security measures, including those for similar systems, to prevent recurrence.

  • Contact Information

If you have any questions or concerns regarding this matter, please contact us at the contact details below.

Mazda Motor Corporation - Inquiry Form: https://mag.mazda.jp/enq/pub/common/svaccinqen

If you receive any suspicious emails or messages claiming to be from Mazda or related parties, please do not open any links or attachments.

We again sincerely apologize for the significant inconvenience and concern this incident has caused.

###