Four days before its fiscal year closed, a Kyoto company that makes professional-use shampoos and treatments sold only through hairdressers, not drugstores, found ransomware on its servers. By the time COTA CO., LTD. sorted out the damage, it had missed the legal deadline for its annual securities report and told Japan's financial regulator that its own internal controls had failed.
The company told the Kinki Local Finance Bureau on August 31, 2026 that unauthorized third-party access infected some servers with ransomware on March 27 and triggered a system failure. It disconnected every server from its network to contain the damage, set up a crisis task force, and brought in outside forensic investigators.
The timing was awkward: the attack hit four days before the March 31 fiscal year-end, just as the company needed to pull data for its books. Staff closed the accounts by hand, the audit took longer than usual, and the annual securities report did not arrive until August 31, five months after the fiscal year ended and past the statutory deadline.
COTA's own conclusion was blunt. It told regulators its company-wide internal controls and its IT general controls contained a material weakness that had to be disclosed, and that financial-reporting controls were not effective as of March 31, 2026. The company said it had already recognized the importance of cybersecurity and had some countermeasures in place, but its risk assessment and response fell short. Because the weakness surfaced on the day of the attack itself, there was no time left in the fiscal year to fix it.
None of this shows up in the headline numbers. Revenue rose 2.4% to ¥9.60bn, a record for a 28th consecutive year of growth. Ordinary profit climbed 12.6% to ¥2.07bn and net income rose 10.1% to ¥1.44bn.
| Metric | Year to March 2025 | Year to March 2026 |
|---|---|---|
| Revenue | ¥9.38bn | ¥9.60bn |
| Operating profit | ¥1.83bn | ¥2.00bn |
| Ordinary profit | ¥1.83bn | ¥2.07bn |
| Net income | ¥1.30bn | ¥1.44bn |
| Dividend per share | ¥20 | ¥20 |
The incident even flattered one line item: with sales events canceled because of the outage, selling and administrative costs fell 0.5% to ¥4.67bn even as sales grew. COTA booked a separate ¥27mn special loss for its response to the system failure, and its audit fee rose to ¥21mn from ¥17mn, including ¥3mn billed specifically for the extra procedures the incident required. For the year now underway, management is budgeting for higher selling and administrative costs to cover cybersecurity strengthening, on top of planned pay increases and new hiring.
Remediation work now under way includes forensic tracing of how the intruder got in, fixes to the vulnerabilities that were found, a broader sweep for other weaknesses across its systems, and tighter network monitoring meant to catch the next intrusion earlier.
The same day it disclosed the control failure, COTA's president signed the routine certification confirming the delayed securities report was accurate. The regulatory record for August 31, 2026 now holds both documents: one attesting the numbers are right, the other explaining why the company almost could not produce them on time.
