Summary
Japanese telecommunications giant KDDI, the country’s second-largest mobile carrier with $32.4 billion in annual revenue, has confirmed that a breach of an email platform used by five internet service providers exposed the data of over 12 million people. The compromised ISPs include STNet, JCOM, Chubu Telecommunications C, NIFTY Corporation, and BIGLOBE.
According to KDDI’s July 6 update, attackers initially breached the platform on May 16 by exploiting a zero-day vulnerability in third-party software — a flaw the software vendor had not yet identified at the time. The breach was discovered on June 17, at which point KDDI blocked attacker access and deployed endpoint detection and response (EDR) software. A forensic audit completed on June 23 confirmed the vulnerability had been addressed.
The exposed data includes 12,233,087 email addresses and 7,616,173 passwords. KDDI noted that some passwords were stored in hashed or encrypted form but did not specify how many were stored in plaintext. The company is now working with affected ISPs to force mandatory password changes for all impacted accounts.
Source
BleepingComputer · KDDI Official Statement (PDF)
Commentary
A breach affecting 12 million email accounts via a zero-day in unnamed third-party software is a stark reminder of supply chain risk in telecom infrastructure. The 32-day dwell time between initial compromise and detection is concerning but not unusual for zero-day exploitation scenarios. The fact that KDDI cannot clearly confirm how many passwords were stored in plaintext raises serious questions about credential hygiene across its ISP partners.
Organizations managing email infrastructure for millions of users should take note: if your password storage practices vary across partner platforms, a single breach can cascade far beyond the initial point of compromise.
