SHINDO4

Chubu Electric Power

Contact records (total)~74,100people

POSSIBLE LEAKPhone number / Messages / email bodiesUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Aug 4, 2026
Detected
Jul 29, 2026
Detection to disclosure
6 days
Leak
Leak possible
Type
Unauthorized access
Status
Contained
Security spend
Measures, no amount
Compensation
Not announced
Corporate number
3180001017428

What leaked

Business dataCompany or organization name
Employment & HRDepartment, Job title
IdentityFull name
ContactEmail address, Phone number
Communications & contentSome officers' and employees' emails

Not leaked

  • No leak of electricity or gas customer data has been confirmed

How many

  • Contact records (total) ~74,100 people
  • Group officers, employees and contractor staff ~71,700 people
  • Related agencies, municipalities and business partners ~2,400 people

Who is affected

  • Related agencies, municipalities, business partners
  • Group officers and employees
  • Contractor staff

Cause

Credentials for some systems were misused

Timeline

  1. Detected
  2. Contained
  3. First disclosure

Response

  • Revoked credentials
  • Blocked the entry point
  • Forensic investigation

Revoked the credentials used and blocked the source of the access; confirmed no impact on power supply or customer systems; investigated with outside specialists

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Expect targeted phishing posing as HR or interview contacts
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Passkeys or MFA for every account; monitor leaked credentials and rotate API keys
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources