Aflac’s Tokyo arm, Sapporo, Nidec and KDDI all disclosed data breaches, but the more important question is what the notices do not yet explain: how access, exposure and verification were handled.