Kyushu Electric Power data breach 2026: Regional utility Kyushu Electric Power disclosed on June 8, 2026 that a subsidiary lost an external backup drive containing personal information for up to 10.9 million customer accounts—one of Japan’s largest utility privacy incidents in recent memory. The missing solid-state device held names, service addresses, electricity usage figures, telephone numbers, and retail electricity provider names for contracts between July 2016 and January 2024. Kyushu Electric said bank and credit card data were not stored on the drive and promised individual notifications to affected customers.
What is Kyushu Electric Power
Kyushu Electric Power Co. (九州電力) is one of Japan’s major regional electric utilities, supplying power across Kyushu—the southwestern island home to Fukuoka, Kumamoto, Nagasaki, and other prefectures with a combined population of about 12.6 million. Like many deregulated markets, the group includes transmission/distribution subsidiaries and retail electricity brands; this incident was announced by Kyushu Electric Power Transmission and Distribution Co., the grid operator handling customer billing and service data for millions of households and businesses.
Timeline: from backup to police report
- April 27, 2026 — IT staff copied customer data to a palm-size external SSD because primary server storage was full during routine backup work (Asahi Shimbun).
- April 27–May 26 — The SSD remained in a server-room cabinet; reporting states the cabinet was left unlocked and the drive was not password-protected.
- May 26, 2026 — Staff returned for another task and discovered the drive missing.
- June 4, 2026 — Kyushu Electric filed a police report suspecting theft (BleepingComputer).
- June 8, 2026 — Subsidiary published an official customer notice (Kyuden press release).
What data was exposed
Kyushu Electric’s announcement and English-language trade press agree the lost SSD could contain:
- Customer names
- Service location addresses (where electricity is delivered)
- Electricity usage data (consumption history useful for occupancy inference)
- Telephone numbers
- Names of retail electricity providers (relevant in Japan’s liberalized power market)
The company stated the backup covered contracts in the Kyushu region—excluding some remote islands—between July 2016 and January 2024. Up to 10.9 million accounts may be involved.
What was not exposed
Kyushu Electric explicitly said bank account information and credit card data were not stored on the missing SSD. That narrows immediate payment fraud risk but does not eliminate phishing or impersonation scams citing real usage or address details.
Physical security failures that matter
Unlike ransomware headlines dominating 2026, this breach is a physical media loss. BleepingComputer highlighted compounding control failures: an unencrypted portable drive, an unlocked cabinet inside a biometrically protected server room, and broad contractor access—57 people from ten contractor firms could enter the room during the month the SSD vanished. Investigators interviewed personnel but had not recovered the device at initial disclosure.
For searchers asking whether this was a cyberattack: public reporting frames the event as suspected theft of backup media, not network intrusion—though the outcome for victims (PII in unknown hands) resembles many digital leaks.
Who is at risk
Any Kyushu Electric customer whose contract falls in the July 2016–January 2024 window and whose data was included in the April 27 backup should assume exposure until notified otherwise. Businesses with multiple service locations may appear multiple times. Retail electricity customers may see provider names that help scammers craft convincing “switching fee” or “bill correction” lures.
Action items for Kyushu Electric customers
- Wait for official Kyushu Electric / Kyuden mail or web notices—do not trust SMS or email links that arrive first.
- Verify payment changes only through numbers on your existing paper bill or the official Kyuden customer portal.
- Be skeptical of callers citing your real address, phone, or kWh usage; accurate details may come from the leak, not legitimate support.
- Report impersonation to local police if someone uses leaked fragments to demand immediate payment or bank transfers.
- Document contract IDs from legitimate bills so you can compare against future scam messages.
- Businesses should warn facilities staff about fake “urgent disconnection” calls referencing real service addresses.
Not the same as the 2024 Kyuhen ransomware breach
BreachHistory separately catalogs a 2024 Kyuhen affiliate ransomware incident affecting on the order of 374,000 records. The June 2026 SSD loss is a distinct event with a much larger ceiling (10.9M accounts) and a non-ransomware root cause.
FAQ
Was Kyushu Electric hacked online?
Public reporting describes a missing backup drive and suspected physical theft, not a network intrusion. Customer data still left organizational control.
Were passwords or payment cards leaked?
Kyushu Electric said bank and credit card data were not on the SSD. Passwords were not listed among exposed fields in English reporting.
How many people are affected?
Up to 10.9 million accounts per the company—among the largest 2026 utility disclosures globally.
Canonical record: Kyushu Electric 2026 lost SSD breach on BreachHistory.
Sources: Kyuden official notice, Asahi Shimbun, BleepingComputer