SHINDO3
Chugoku Electric
The Chugoku Electric Power Co., Inc.
Personal data15,566people
POSSIBLE LEAKFull name / Email addressUnauthorized access · Contained
Open in the live monitor ▶- Disclosed
- Apr 28, 2025
- Detected
- Apr 21, 2025
- Detection to disclosure
- 7 days
- Leak
- Leak possible
- Type
- Unauthorized access
- Status
- Contained
- Security spend
- Not checked yet
- Compensation
- Not announced
What leaked
IdentityFull name
ContactWork email address
Account dataUser ID
CredentialsEncrypted passwords
How many
- Employees, former employees, contractor staff and others 15,566 people
Who is affected
- Employees of the company and group company Chugoku Electric Power Transmission & Distribution
- Former employees
- Contractor staff
Cause
Some of the devices used to connect to the internal network from outside, linked to a system holding employee personal data, had configuration flaws and were compromised
Timeline
- Detected
- Contained
- Individuals notified
- Reported to authority
- Date of the Security NEXT report
Response
- Blocked the entry point
- Password reset
- Notified individuals
Disconnected the compromised device from the network the same day, informed the people concerned and asked them to change passwords. Reported to the Personal Information Protection Commission
What you should do
- Change this password and every account that reused it now. Weak passwords crack even when hashed or encrypted. Switch to a passkey where offered
- Don't open links in emails from this company. The apology email itself may be fake
- Expect targeted phishing posing as HR or interview contacts
- Check the company's notice to see if you're affected
Lessons for companies
- Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
- Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
- Run red teaming and AI-assisted hardening, and publish how much you invest
Sources
- Security NEXT News · Apr 28, 2025