FAQ Regarding Unauthorized Access to Our Website
2026.08.19
Q1. What happened?
We have confirmed that our website was accessed by an unauthorized third party.
The results of our investigation determined that this incident exploited a vulnerability in software used on the website.
Based on the results of our ongoing investigation, there seems to be no evidence that the affected information has been disclosed to external parties, at this time.
However, as the possibility of unauthorized access to personal information cannot be completely ruled out, we are continuing our investigation.
Q2. Has information leakage been confirmed?
Based on the results of our ongoing investigation, there seems to be no evidence that the affected information has been disclosed to external parties, at this time.
As the possibility of unauthorized access to personal information cannot be completely ruled out, we are continuing our investigation.
Q3. When did the incident occur?
According to our investigation, the initial unauthorized access occurred at approximately 1:00 a.m. JST on July 20, 2026. The incident itself was identified on July 24, 2026.
Q4. Is the unauthorized access still ongoing?
On July 24, 2026, we immediately applied security updates to the software used on our website. At this time, we have not identified any incidents or suspicious activity.
Q5. What measures have been taken to prevent recurrence?
Following the confirmation of the unauthorized access, we promptly applied the necessary security updates to the software used on our website.
In addition, we will continue working closely with external cybersecurity experts and bolster safeguards against future occurrences.
Q6. Has my personal information been affected?
At this time, it has not been determined whether any specific customer’s information has been affected. Should any new facts come to light, we will promptly provide an update.
Q7. What information may have been affected?
The information that may have been affected, based on what has been identified to date, is as follows:
| Affected Individuals | Information Involved |
|---|---|
| Users registered on our website (including provisional registrations) | Name(Full Members Only) *1, Member ID, Email Address, Hashed Password (Full Members Only)*1 |
| Individuals who submitted inquiries through our website | Name, Title, Organization Name, Email Address, Telephone Number, Address, Country, Postal Code, Inquiry Details*2 |
*1 Passwords are stored in a hashed format that cannot be reversed to reveal the original value.
*2 The inquiry form contains optional fields; therefore, not all of the information listed above is necessarily included in every inquiry record.
Q8. Has my password been compromised?
At this time, we have not identified any evidence indicating that passwords have been compromised.
In addition, we have confirmed that the affected password information is stored in a protected format that cannot be directly viewed by third parties, and that the original passwords cannot be easily restored from this data. However, we cannot completely rule out the possibility that information associated with this incident may have been accessed or obtained by an unauthorized party.
Should any new information become available, we will provide updates promptly.
If you have any concerns, we encourage you to consider changing your password using the link below.
Password Change Page:
https://www.nidek-intl.com/log-in/?swpm_redirect_to=/membership-profile/
Please note that you will be required to enter your User ID and current password before proceeding to the password change page.
Q9. Why am I receiving this individual notification now?
We sincerely apologize for the time it has taken to provide this individual notification.
Upon confirming the unauthorized access, we promptly disclosed the incident on our website.
Before issuing individual notifications, we conducted an investigation to assess the scope of the impact and identify the information that may have been affected, so that we could provide accurate information regarding this incident.
As a result, additional time was required before we could send individual notifications.
Q10. I would like my inquiry information to be deleted.
The historical inquiry data, including inquiry details, has been removed from the website.
However, for the purposes of investigating this incident and carrying out any necessary safeguards, the inquiry data is being retained and managed appropriately in a separate location.
Q11. What should I do?
Please be cautious of suspicious emails claiming to be from our company.
If you receive a suspicious email, please do not access any URLs contained in the message or provide any personal information.
Q12. Should I change my email address?
At this time, we have not identified any information that requires you to change your email address immediately. However, please remain vigilant for suspicious emails or communications that may appear to come from our company.
If you receive any suspicious communications, please do not access any URLs contained in the message or provide any personal information.
Q13. Do I need to change my password?
At this time, we have not identified any evidence indicating that passwords have been compromised.
In addition, we have confirmed that the affected password information is stored in a protected format that cannot be directly viewed by third parties, and that the original passwords cannot be easily restored from this data.
However, we cannot completely rule out the possibility that information associated with this incident may have been accessed or obtained by an unauthorized party.
Should any new information become available, we will provide updates promptly.
If you have any concerns, we encourage you to consider changing your password using the link below.
Password Change Page:
https://www.nidek-intl.com/log-in/?swpm_redirect_to=/membership-profile/
Please note that you will be required to enter your User ID and current password before proceeding to the password change page.
Q14. Why did this incident occur?
As a result of our investigation, we confirmed that the unauthorized access was carried out by exploiting a vulnerability in software used on our website.
Upon detecting the unauthorized access, we immediately updated the affected software to address the vulnerability. We have also engaged an external cybersecurity specialist to conduct an independent investigation and assess the impact of the incident.
Q15. What responsibility is the Company taking regarding this incident?
We sincerely apologize for the concern and inconvenience this incident has caused our customers.
We take this matter very seriously and are continuing to investigate the facts and assess the scope of any potential impact. We are also working to implement measures to prevent similar incidents from recurring.
We will continue to respond appropriately based on the results of our investigation.
Q16. Will compensation be provided for any damages resulting from this incident?
At this time, we are continuing to investigate the scope and circumstances of the impact resulting from this incident. Therefore, no policy regarding compensation for damages has been determined at this stage.
Any inquiries or concerns raised by customers will be reviewed on a case-by-case basis, and we will respond appropriately based on the individual circumstances.
If you have any questions or concerns regarding this matter, please contact us at:
info@nidek.co.jp
Q17. How many Members may be affected?
The investigation is currently ongoing. Based on the information available at this time, approximately 28,000 members may have been affected by this incident.
Q18. Have you reported this incident to the Personal Information Protection Commission?
In accordance with applicable laws and regulations, we are proceeding with reporting to and consulting with Japan’s Personal Information Protection Commission, as well as other relevant authorities.










































