Japanese energy firm loses drive with data of 10.9 million clients

2026-06-12T01:23:31Z86ec1eb16734133d4fab9083f06df38ddaf6138a8ae13cc2a7b4a3bd9f70f1c4
AudiA6CISA BOD 26-04CVE-2026-35273CVE-2026-5027GitHubIvanti SentryJDY botnetKyushu ElectricLangflowMaine breach portalMiasmaPeopleSoftShinyHuntersbotnetcredential-stealercrypto-launderingdata breachdata theftmisinformation campaignnpmpatchingphysical drive lossransomwaresupply-chainzero-day

What happened

Multiple active and high-impact incidents: Oracle warned of a critical PeopleSoft zero-day (CVE-2026-35273) enabling unauthenticated RCE that is being exploited in ShinyHunters data-theft attacks; a high-severity path traversal in Langflow (CVE-2026-5027) and a maximum-severity Ivanti Sentry flaw are also under active exploitation. Large-scale data incidents and enforcement include Kyushu Electric losing a physical drive with personal data of ~10.9 million customers, Nottingham University student-records breach (~450k affected), and South Korea fining Coupang ~$409M after a massive breach. Not

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
86ec1eb16734133d4fab9083f06df38ddaf6138a8ae13cc2a7b4a3bd9f70f1c4
Enrichment time
2026-06-12T01:23:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.