Kyushu Electric Power Co. is bracing for one of Japan's largest data exposures of the year after a subsidiary confirmed on June 8 that an unencrypted SSD holding the personal information of up to 10.9 million customers vanished from its Fukuoka head office. Kyushu Electric Power Transmission and Distribution Co. has filed a police report for suspected theft of the palm-size device, which stored names, addresses, and phone numbers for both individuals and corporations. Officials say no misuse of the data has been confirmed to date, but the investigation is treating both accidental loss and theft as live possibilities.
What Happened
The incident traces back to April 27, when a contractor backed up customer data onto a small SSD inside the company server room and placed it in a storage cabinet. The drive was not noticed missing until nearly a month later, on May 26, when the same worker returned to perform another task and found it gone. That month-long blind spot is the heart of the failure: the device sat unaccounted for through late spring before anyone realized it had disappeared.
The server room itself was not loosely guarded. Entry required an ID card and biometric authentication. But access control at the door means little when 57 employees from 10 separate contractor companies all held authorization to the area during the window the SSD went missing. The pool of people with legitimate physical access was large enough that narrowing down a single point of failure will be difficult.
What Was Taken
The missing SSD contains records for up to 10.9 million customers, covering contracts across the Kyushu region (excluding remote islands) from July 2016 through January 2024. It also includes data for individuals who applied to move between October 2025 and April 2026. The exposed fields are names, addresses, and phone numbers for both individual and corporate customers.
Kyushu Electric stressed that sensitive financial details, including bank account and credit card information, were not stored on the drive. That limits the immediate fraud surface, but a dataset of this scale linking names to verified addresses and phone numbers is high-value fuel for targeted phishing, smishing, and social engineering campaigns against a known utility customer base.
Why It Matters
This is a textbook physical data-loss event at critical infrastructure scale, and it underscores how the weakest link is often not the network perimeter but a cabinet drawer. A utility invested in biometric door controls still lost millions of records because the data itself was left unencrypted and unlocked behind that door. For defenders, the lesson is that perimeter security and data-at-rest protection are separate problems, and solving one does not solve the other.
The breach also lands squarely in the contractor and supply chain risk category. With 57 workers from 10 vendors holding access, the trust boundary extended far beyond Kyushu Electric's own staff. The episode echoes prior large Japanese exposures such as the NTT West leak of 9 million records, and reinforces that insider-adjacent physical access remains a chronic, under-defended threat.
The Attack Technique
No intrusion technique in the conventional sense is required here. If theft is confirmed, this is a physical exfiltration of an unencrypted, removable storage device by someone with authorized access to a secured room. The enabling conditions were entirely procedural: the SSD was not password-protected, it was stored in an unlocked cabinet, and there was no inventory or check-out process that would have flagged its absence for nearly a month.
The combination of removable media, missing encryption, and absent tracking turns a single small drive into a catastrophic loss vector. Whether the device was stolen or simply misplaced, the controls that should have contained the damage, namely encryption and access logging, were not in place.
What Organizations Should Do
- Encrypt all data at rest, especially on removable media. Full-disk or hardware encryption on the SSD would have rendered this loss a non-event regardless of who took the device.
- Eliminate unlocked storage for sensitive media. Locked cabinets, safes, or media vaults with key control must back up any door-level access controls.
- Implement asset tracking and check-out logging for all portable storage, so a missing device triggers an alert in hours, not weeks.
- Apply least privilege to physical access. Reassess why 57 people across 10 vendors needed standing access to a sensitive server room, and scope contractor access to specific tasks and time windows.
- Log and monitor physical entry against expected activity, correlating badge and biometric events with scheduled work to detect anomalous presence.
- Minimize and segment bulk data backups, avoiding the creation of single drives that aggregate millions of customer records when narrower exports would suffice.
Sources: Massive data breach feared at Kyushu Power as SSD missing | The Asahi Shimbun