SYS::ONLINE
Wasteland.
Briefs1677
Issues21
SinceFeb 2026
LIVE
▣ Breach KYUSHU-ELECTRIC-PO 2026-06-09

Kyushu Electric Power: Missing SSD Exposes 10.9 Million Records

"Kyushu Electric Power Co. is bracing for one of Japan's largest data exposures of the year after a subsidiary confirmed on June 8 that an unencrypted SSD holding the personal information of up to 10.9 million customers…"

Kyushu Electric Power Co. is bracing for one of Japan's largest data exposures of the year after a subsidiary confirmed on June 8 that an unencrypted SSD holding the personal information of up to 10.9 million customers vanished from its Fukuoka head office. Kyushu Electric Power Transmission and Distribution Co. has filed a police report for suspected theft of the palm-size device, which stored names, addresses, and phone numbers for both individuals and corporations. Officials say no misuse of the data has been confirmed to date, but the investigation is treating both accidental loss and theft as live possibilities.

What Happened

The incident traces back to April 27, when a contractor backed up customer data onto a small SSD inside the company server room and placed it in a storage cabinet. The drive was not noticed missing until nearly a month later, on May 26, when the same worker returned to perform another task and found it gone. That month-long blind spot is the heart of the failure: the device sat unaccounted for through late spring before anyone realized it had disappeared.

The server room itself was not loosely guarded. Entry required an ID card and biometric authentication. But access control at the door means little when 57 employees from 10 separate contractor companies all held authorization to the area during the window the SSD went missing. The pool of people with legitimate physical access was large enough that narrowing down a single point of failure will be difficult.

What Was Taken

The missing SSD contains records for up to 10.9 million customers, covering contracts across the Kyushu region (excluding remote islands) from July 2016 through January 2024. It also includes data for individuals who applied to move between October 2025 and April 2026. The exposed fields are names, addresses, and phone numbers for both individual and corporate customers.

Kyushu Electric stressed that sensitive financial details, including bank account and credit card information, were not stored on the drive. That limits the immediate fraud surface, but a dataset of this scale linking names to verified addresses and phone numbers is high-value fuel for targeted phishing, smishing, and social engineering campaigns against a known utility customer base.

Why It Matters

This is a textbook physical data-loss event at critical infrastructure scale, and it underscores how the weakest link is often not the network perimeter but a cabinet drawer. A utility invested in biometric door controls still lost millions of records because the data itself was left unencrypted and unlocked behind that door. For defenders, the lesson is that perimeter security and data-at-rest protection are separate problems, and solving one does not solve the other.

The breach also lands squarely in the contractor and supply chain risk category. With 57 workers from 10 vendors holding access, the trust boundary extended far beyond Kyushu Electric's own staff. The episode echoes prior large Japanese exposures such as the NTT West leak of 9 million records, and reinforces that insider-adjacent physical access remains a chronic, under-defended threat.

The Attack Technique

No intrusion technique in the conventional sense is required here. If theft is confirmed, this is a physical exfiltration of an unencrypted, removable storage device by someone with authorized access to a secured room. The enabling conditions were entirely procedural: the SSD was not password-protected, it was stored in an unlocked cabinet, and there was no inventory or check-out process that would have flagged its absence for nearly a month.

The combination of removable media, missing encryption, and absent tracking turns a single small drive into a catastrophic loss vector. Whether the device was stolen or simply misplaced, the controls that should have contained the damage, namely encryption and access logging, were not in place.

What Organizations Should Do

Sources: Massive data breach feared at Kyushu Power as SSD missing | The Asahi Shimbun