All Breaches
May 26, 2026 Verified Sensitive Record Energy

Kyushu Electric TD 2026 Data Breach

The Kyushu Electric TD 2026 data breach is a physical-security incident in which Kyushu Electric Power Transmission and Distribution confirmed that an unencrypted SSD containing customer information disappeared from an unlocked cabinet in a secured server room. The SSD was placed there after an April 27, 2026 backup and was found missing during preparation for the next operation on May 26.

The company's final July 8 report replaced the initial upper bound of 10.9 million with a detailed count. After removing duplicate records with the same name and address, the SSD held 10.03 million individual-customer information records and 3.51 million records associated with organizations, equipment, or contracts, for 13.54 million customer-information records in total. LeakData uses the 10.03 million individual-record count in pwnCount.

How Did the SSD Go Missing?

When storage servers for two operational systems ran short of capacity, the company began temporarily moving monthly backups to an external SSD in January 2026. Two contractor employees performed the work. The server room had multiple physical controls including identity, card, and biometric checks and cameras, but the cabinet holding the SSD was not locked.

The SSD was returned to the cabinet after work on April 27 and could not be found on May 26. The company reviewed access records, interviewed relevant people, and searched the location without recovering it. It investigated all possibilities, including unauthorized removal, and filed a police report on June 4. The public report does not conclusively identify who took the device or how it left the server room.

What Is the Current Record Count?

The initial June 8 announcement referred to at most 10.9 million customer accounts. The company later reviewed moves, name changes, and duplicate name-address combinations. Its July 8 report identified 10.03 million individual-information records, 3.51 million organizational or other contract records, and a combined total of 13.54 million; 7.14 million were associated with contracts still active in June 2026.

The 10.03 million figure is a count of individual-customer information after identical name and address duplicates were removed; it does not prove that every row maps to a unique living person. Contracts tied to equipment such as streetlights and traffic signals may appear in the company-and-other category. To avoid inflating person impact, LeakData limits pwnCount to individual records and uses the disclosed 13.54 million total in totalRecords.

What Information Was on the SSD?

Transmission-system backups contained customer names, service or supply-location addresses, electricity consumption, retail electricity-provider names, and supply-point identification numbers. The switching-support system additionally held fields such as telephone numbers, contracted power, application dates, and application types. Phone numbers appeared only in the smaller group associated with that second system.

The company explicitly said the two systems on the SSD did not contain bank-account, credit-card, or email-address information. Those fields are not added as data classes. The device itself had no encryption or password protection, creating a risk that someone with physical possession could read the data; layered server-room controls did not independently protect a device after removal.

Difference Between Loss and Confirmed Leakage

The confirmed event is the disappearance of an unprotected SSD holding personal data and the inability to locate it. As of July 8, the company said it had found no evidence that data appeared online or that the SSD was offered for sale. This record therefore does not claim that records were published on the internet or used by a specific attacker.

A data breach does not require an online attack; losing organizational control of portable media holding personal information is also a confidentiality and security incident. The lack of encryption and possibility of unauthorized removal expose millions of records to potential access even without proof that the drive was read. The narrative verifies the physical loss without elevating a possible extraction into a confirmed claim.

Company Response and Outcome

Kyushu Electric TD notified the Personal Information Protection Commission, the Agency for Natural Resources and Energy, and other regulators, and a police investigation began. The company planned phased direct-mail notifications from early August, disclosure of the fields held for each customer, and a dedicated call center. It warned about suspicious communications because customers were not required to complete any additional procedure.

The final report identified weak necessity and risk approval for external media, unlocked physical storage, missing encryption and password protection, and insufficient contractor oversight as root causes. Its new approach is to avoid external media, prevent unauthorized removal, and make any removed device unreadable; policies, approvals, training, and compliance checks were strengthened.

How to Interpret This LeakData Record

This record covers an unencrypted customer backup discovered missing on May 26, 2026 and potentially lost at some point between April 27 and May 26. pwnCount represents 10.03 million individual-information records, while totalRecords represents 13.54 million individual and other customer or contract records. The earlier 10.9 million headline is superseded by the newer detailed official count.

Verified fields include names, service addresses, electricity consumption, provider names, supply-point numbers, and, in selected records, telephone and contract or application information. Bank, card, and email data were absent, and online publication or misuse was not confirmed. The record explains the risk from a missing unencrypted device without adding an unverified data-leak outcome.

10 Million
Affected Accounts
7
Data Types
Critical
Severity
Yes
Verification

Exposed Data Types

7
Customer names
Service location addresses
Electricity usage data
Retail electricity provider names
Supply point identification numbers
Phone numbers (selected records)
Contract and application information

Additional Information

Added DateJuly 27, 2026
Breach DateMay 26, 2026
Domainkyuden.co.jp
SourceMissing unencrypted external SSD containing customer backups
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information