Weekday Japan business intelligence for finance professionals.

Join the list
Tokyo Brief東 京 ブ リ ー フ

Japan's day, wrapped and delivered by morning.

Article

Ransomware Attack Forces Hair-Care Maker COTA to Admit Its Financial Controls Failed

A ransomware attack four days before its fiscal year-end forced manual bookkeeping at Kyoto salon-products maker COTA, delayed its annual filing past the legal deadline, and led it to tell regulators its internal controls had failed, even as revenue climbed to a record for a 28th straight year.

Aug 31, 20263 min readCOTA CO.,LTD.4923
Illustration of disconnected server racks beside shelves of hair-care product bottles, representing a ransomware-driven system shutdown at a salon-products manufacturer.

Four days before its fiscal year closed, a Kyoto company that makes professional-use shampoos and treatments sold only through hairdressers, not drugstores, found ransomware on its servers. By the time COTA CO., LTD. sorted out the damage, it had missed the legal deadline for its annual securities report and told Japan's financial regulator that its own internal controls had failed.

The company told the Kinki Local Finance Bureau on August 31, 2026 that unauthorized third-party access infected some servers with ransomware on March 27 and triggered a system failure. It disconnected every server from its network to contain the damage, set up a crisis task force, and brought in outside forensic investigators.

The timing was awkward: the attack hit four days before the March 31 fiscal year-end, just as the company needed to pull data for its books. Staff closed the accounts by hand, the audit took longer than usual, and the annual securities report did not arrive until August 31, five months after the fiscal year ended and past the statutory deadline.

COTA's own conclusion was blunt. It told regulators its company-wide internal controls and its IT general controls contained a material weakness that had to be disclosed, and that financial-reporting controls were not effective as of March 31, 2026. The company said it had already recognized the importance of cybersecurity and had some countermeasures in place, but its risk assessment and response fell short. Because the weakness surfaced on the day of the attack itself, there was no time left in the fiscal year to fix it.

None of this shows up in the headline numbers. Revenue rose 2.4% to ¥9.60bn, a record for a 28th consecutive year of growth. Ordinary profit climbed 12.6% to ¥2.07bn and net income rose 10.1% to ¥1.44bn.

COTA's year to March 2026
Non-consolidated results; yen figures shown in compact notation. Source: COTA annual securities report.
MetricYear to March 2025Year to March 2026
Revenue¥9.38bn¥9.60bn
Operating profit¥1.83bn¥2.00bn
Ordinary profit¥1.83bn¥2.07bn
Net income¥1.30bn¥1.44bn
Dividend per share¥20¥20

The incident even flattered one line item: with sales events canceled because of the outage, selling and administrative costs fell 0.5% to ¥4.67bn even as sales grew. COTA booked a separate ¥27mn special loss for its response to the system failure, and its audit fee rose to ¥21mn from ¥17mn, including ¥3mn billed specifically for the extra procedures the incident required. For the year now underway, management is budgeting for higher selling and administrative costs to cover cybersecurity strengthening, on top of planned pay increases and new hiring.

Remediation work now under way includes forensic tracing of how the intruder got in, fixes to the vulnerabilities that were found, a broader sweep for other weaknesses across its systems, and tighter network monitoring meant to catch the next intrusion earlier.

The same day it disclosed the control failure, COTA's president signed the routine certification confirming the delayed securities report was accurate. The regulatory record for August 31, 2026 now holds both documents: one attesting the numbers are right, the other explaining why the company almost could not produce them on time.