When a leader's broker is fenced, the active controller elects a new leader from the ISR, raises the leader epoch and records the change in the metadata log, so no committed record is lost. With no ISR member left the partition goes offline, unless unclean.leader.election.enable=true (default false) lets an out-of-sync replica lead and lose whatever it lacks. Kafka 4 129 .x adds eligible leader replicas (ELR, KIP-966): when the ISR falls below min.insync.replicas, replicas that hold everything up to the HW move to the ELR (broker 6 in The In-Sync Replica Set) and can still be elected cleanly if the last ISR member dies.
Failures leave leadership piled on survivors: broker 5 led all three partitions afterward. With auto.leader.rebalance.enable (the default) the controller returns leadership to preferred replicas every leader.imbalance.check.interval.seconds (300); kafka-leader-election.sh --election-type PREFERRED --all-topic-partitions does it at once, and here moved the leaders back to brokers 4, 5 and 6.