← All stories
● Covered by 3 sources · 3 reportsMedium impact

12 Million Affected in KDDI Data Breach, Exploiting Zero-Day Vulnerability

🔄 Updated 85d ago — new reporting from SecurityWeek
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • 12.2 million emails and 7.6 million passwords exposed.
  • Zero-day vulnerability exploited in third-party software.
  • KDDI's own email services unaffected by breach.
  • Incident affected email systems of five ISPs.
  • Vulnerability patched; mandatory password resets enforced.

Overview of the Security Breach

KDDI, a prominent Japanese telecommunications company, reported that a cyberattack occurred in June, resulting in the exposure of 12.2 million email addresses and 7.6 million passwords. The affected email system serves five major internet service providers in Japan. The breach stemmed from a zero-day vulnerability in a third-party software used in the system.

KDDI's Response and Measures

Following the detection of unauthorized access on June 17, KDDI promptly blocked the attackers and took action to secure vulnerable accounts. The company patched the exploited software flaw and enforced mandatory password resets for affected users to mitigate potential risks of account hijacking. Additionally, KDDI's investigation confirmed that its own consumer email services, operating on a different infrastructure, were not compromised.

Background on the Affected ISPs

The compromised email platform is utilized by five ISPs: STNet, JCOM, Chubu Telecommunications C, NIFTY Corporation, and BIGLOBE. The security breach potentially affected both current and former customers' accounts, including some with inactive status. While many exposed passwords were stored in a secured format, details about encryption methods used were not fully disclosed.

Implications for the Telecom Sector

This incident underlines the persistent challenges faced by telecom companies due to vulnerabilities in third-party software. The coordination between KDDI and the affected ISPs emphasizes the importance of collaborative security measures and highlights the necessity for ongoing vigilance and rapid response to zero-day threats to safeguard customer data.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

KDDI confirmed a June breach affected 12.2 million email addresses and 7.6 million passwords. A zero-day vulnerability was exploited, prompting urgent password resets for all compromised accounts.

KDDI announced that a data breach impacted over 12 million users, exposing email addresses and passwords via a compromised email platform used by multiple ISPs. The company is working to secure accounts and has implemented measures to prevent future incidents, highlighting the risks of zero-day vulnerabilities in third-party software.

KDDI reported that a cyberattack exposed 12.2 million email addresses and 7.6 million passwords linked to five ISPs. The breach stemmed from a vulnerability in third-party software, which KDDI has patched, ensuring its own services remained secure. This incident highlights ongoing security challenges for Japanese companies amid a rise in cyber incidents.