Japanese energy firm loses drive with data of 10.9 million clients

Japanese energy firm loses drive with data of 10.9 million clients — Cybersecurity | Versia.media

Kyushu Electric Power Co., Inc. has reported a physical security breach that compromises the personal data of over 10 million customers.

In a formal statement, the company stated that its IT staff routinely perform backups to manage server storage. Due to capacity limitations, an external storage device was used for this task on April 27.

The drive was subsequently stored in a server room cabinet protected by multiple layers of physical security. On May 26, when IT staff attempted to retrieve it, they discovered the cabinet had been left unlocked and the drive was missing.

Kyushu Electric Power Company is a major regional electric utility in Japan, providing electricity throughout the Kyushu region, covering the prefectures of Fukuoka, Saga, Nagasaki, Kumamoto, Oita, Miyazaki, and Kagoshima.

The Kyushu region has a total population of 12.6 million, and the company stated that the incident affects up to 10.9 million accounts.

The data on the now-missing drive includes:

Customer names

Service location addresses

Electricity usage data

Telephone numbers

Names of retail electricity providers

Other related information

The company has confirmed that no bank account details or credit card information were stored on the drive. It also pledged to notify affected customers individually in the coming period.

Since the hard drive was lost, the firm has interviewed all personnel who entered the server room and conducted investigations, but has been unable to locate it.

Media reports indicate that 57 individuals had access to the server room, and Kyushu Electric filed a police report on June 4, suspecting that someone had removed the drive.

NHK One reported that Japan's Ministry of Economy, Trade, and Industry has given the company until July 8 to submit a full report on the incident and the preventive measures implemented.

“The company is investigating all possibilities, including unauthorized removal of the device, but it has not yet been located,” the bulletin states.

The incident has been reported to Japan’s Personal Information Protection Commission and the relevant government authorities.

Test every layer before attackers do

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Related Articles:

SoFi confirms third-party data breach at Hong Kong subsidiary

Medtronic confirms breach after hackers claim 9 million records theft

Ex-school district employee jailed for hacks on former employer

Maine disables data breach notification portal after fake disclosures

Pharma giant Novo Nordisk discloses breach of clinical trials data

← Cybersecurity