The images in this article were generated with artificial intelligence. How we publish
Kyushu Electric Power has confirmed the loss of an external hard drive containing personal data from up to 10.9 million accounts, a figure of the total population resident in the Kyushu region. The company explains that the device was used for a backup on 27 April and, when it was removed from a server booth on 26 May, it was lost; the company filed a complaint with the police on 4 June and has already notified the corresponding data protection authorities.
The scope of the incident goes beyond a simple logistical failure: the disk contained names, supply addresses, power consumption data, telephone numbers and the name of retail suppliers. Although Kyushu Electric claims that there was no bank or credit card information, this combination of data facilitates targeted fraud campaigns, identity supplanting, and can be used to plan physical crimes against homes by knowing consumption patterns that report absences or prolonged presence.

The chronology and circumstances suggest multiple failures in physical and procedural controls: storage in removable support without additional protective measures, a cabin apparently accessible by dozens of people (media cites up to 57 people with access) and the absence - at least temporary - of a chain of custody and CCTV or access records to track the extraction. The Japanese authorities have given specific time-limits to receive information on the investigation and corrective measures, as the local press reports; see NHK's statement Here. and the company's newsletter in DocumentCloud Here..
For the persons concerned, the first actions should be of caution and monitoring. Wait for official notification from the company, register any suspicious communication that mentions personal data or details of the power supply, and be alert to calls and messages that attempt to confirm identities or request payments. Although no financial data have been disclosed, it is prudent to review unusual movements in home-related services and to keep up-to-date the blockade and strong authentication in housing-related accounts.
This case should be considered by companies and critical infrastructure managers as a call for attention to the management of removable support. External disks containing personal or sensitive information should be encrypted, taken only when necessary and registered with a chain of custody. In addition, strict policies of retention, safe data disposal and alternatives to physical means - for example, encrypted backups in solutions managed with granular access controls - reduce the risk area. The guidelines for good practice and safe disposal of supports, such as those of NIST, are a useful resource for designing these processes: see NIST guide.

This incident also exposes weaknesses in staff supervision and in the segmentation of physical access. Registration of access, critical point cameras, periodic audits and permit reviews are operational measures that together reduce the likelihood of unauthorized extraction and facilitate the investigation if an incident occurs. In addition, organizations should practice incident responses that include clear and early communication with users and regulators, and simulations that do not assume that "no one would steal a disk" but validate each protection layer.
From the regulatory point of view, the presentation of the impact to the Japan Personal Information Protection Commission and to the competent ministry is a must; the lack of preventive measures or adequate response could lead to sanctions and loss of public confidence. The episode illustrates why critical infrastructure cannot treat personal data as an operating by-product: public confidence and continuity of service also depend on the correct protection of information. For those who want to follow official updates, the Japanese data protection agency website provides guidance and legal frameworks on the treatment and reporting of leaks: Commission for the Protection of Personal Information (CFP).
Ultimately, this type of incident shows that security is not just digital: physical protection, processes and organizational culture are equally critical. Power companies and other entities with mass data should integrate technical and physical controls, assess the risk of each backup operation and prioritize the reduction of data stored outside controlled environments. For citizens, the recommendation is to remain vigilant, to demand clarity on what data were exposed and what compensation or mitigation the responsible company offers.
Related
More news on the same subject.

GitLab critical alert: emergency patch fixes CVE-2026-19478 allowing to modify or eliminate public projects without credentials
GitLab published an emergency patch on August 17, 2026 to correct critical vulnerability in its self-hosted software (Community and Enterprise Edition) which, under certain cond...

When the MCP server keeps your credentials: the silent attack vector of the IA in production
The incorporation of IA agents into business processes has opened a practical way for production systems and data to be accessible from models: it is called Model Context Protoc...

Critical alert: CVE-2026-58231 in SAP Commerce Cloud could allow remote code execution; patch and urgent mitigation
A critical vulnerability that affects SAP Commerce Cloud, registered as CVE-2026-58231 and with maximum score 10.0 on the CVSS scale, it is being exploited attempts shortly afte...

The massive purchase of expired domains drives fraud, malware and streaming pirate: the business behind the dropcatch
An intelligence report on DNS published by Infoblox and disseminated by specialized media confirms that criminals are buying large-scale expired domains - the so-called dropcatc...

HoneyMyte updates CoolClient with a signed kernel driver to hide processes and protect the C2 channel
Kaspersky has published an analysis that attributes to the actor known as HoneyMyte (also Mustang Panda) an updated version of the CoolClient backdoor that incorporates a signed...

GeoServer on zero-day vulnerability alert in jsonArrayContains with real risk of remote execution
The GeoServer open source project has a zero-day vulnerability that is being actively explored by attackers, according to researchers' public alerts and the watchTowr intelligen...

AmnesiaStealer MacOS malware that steals credentials and controls real-time browser sessions
Security researchers have documented a new malware family aimed at macOS - called AmnesiaStealer - that combines a dropper in shell, an infostealer written in Rust and a remote ...