The miscarriage of a hard drive with data of 10.9 million accounts exposes failures in critical infrastructure security

Author: Published 4 min de lectura 155 reading

The images in this article were generated with artificial intelligence. How we publish

Kyushu Electric Power has confirmed the loss of an external hard drive containing personal data from up to 10.9 million accounts, a figure of the total population resident in the Kyushu region. The company explains that the device was used for a backup on 27 April and, when it was removed from a server booth on 26 May, it was lost; the company filed a complaint with the police on 4 June and has already notified the corresponding data protection authorities.

The scope of the incident goes beyond a simple logistical failure: the disk contained names, supply addresses, power consumption data, telephone numbers and the name of retail suppliers. Although Kyushu Electric claims that there was no bank or credit card information, this combination of data facilitates targeted fraud campaigns, identity supplanting, and can be used to plan physical crimes against homes by knowing consumption patterns that report absences or prolonged presence.

The miscarriage of a hard drive with data of 10.9 million accounts exposes failures in critical infrastructure security
Image generated with IA.

The chronology and circumstances suggest multiple failures in physical and procedural controls: storage in removable support without additional protective measures, a cabin apparently accessible by dozens of people (media cites up to 57 people with access) and the absence - at least temporary - of a chain of custody and CCTV or access records to track the extraction. The Japanese authorities have given specific time-limits to receive information on the investigation and corrective measures, as the local press reports; see NHK's statement Here. and the company's newsletter in DocumentCloud Here..

For the persons concerned, the first actions should be of caution and monitoring. Wait for official notification from the company, register any suspicious communication that mentions personal data or details of the power supply, and be alert to calls and messages that attempt to confirm identities or request payments. Although no financial data have been disclosed, it is prudent to review unusual movements in home-related services and to keep up-to-date the blockade and strong authentication in housing-related accounts.

This case should be considered by companies and critical infrastructure managers as a call for attention to the management of removable support. External disks containing personal or sensitive information should be encrypted, taken only when necessary and registered with a chain of custody. In addition, strict policies of retention, safe data disposal and alternatives to physical means - for example, encrypted backups in solutions managed with granular access controls - reduce the risk area. The guidelines for good practice and safe disposal of supports, such as those of NIST, are a useful resource for designing these processes: see NIST guide.

The miscarriage of a hard drive with data of 10.9 million accounts exposes failures in critical infrastructure security
Image generated with IA.

This incident also exposes weaknesses in staff supervision and in the segmentation of physical access. Registration of access, critical point cameras, periodic audits and permit reviews are operational measures that together reduce the likelihood of unauthorized extraction and facilitate the investigation if an incident occurs. In addition, organizations should practice incident responses that include clear and early communication with users and regulators, and simulations that do not assume that "no one would steal a disk" but validate each protection layer.

From the regulatory point of view, the presentation of the impact to the Japan Personal Information Protection Commission and to the competent ministry is a must; the lack of preventive measures or adequate response could lead to sanctions and loss of public confidence. The episode illustrates why critical infrastructure cannot treat personal data as an operating by-product: public confidence and continuity of service also depend on the correct protection of information. For those who want to follow official updates, the Japanese data protection agency website provides guidance and legal frameworks on the treatment and reporting of leaks: Commission for the Protection of Personal Information (CFP).

Ultimately, this type of incident shows that security is not just digital: physical protection, processes and organizational culture are equally critical. Power companies and other entities with mass data should integrate technical and physical controls, assess the risk of each backup operation and prioritize the reduction of data stored outside controlled environments. For citizens, the recommendation is to remain vigilant, to demand clarity on what data were exposed and what compensation or mitigation the responsible company offers.

Coverage

Related

More news on the same subject.