KDDI, a prominent Japanese telecommunications company, reported that a cyberattack occurred in June, resulting in the exposure of 12.2 million email addresses and 7.6 million passwords. The affected email system serves five major internet service providers in Japan. The breach stemmed from a zero-day vulnerability in a third-party software used in the system.
Following the detection of unauthorized access on June 17, KDDI promptly blocked the attackers and took action to secure vulnerable accounts. The company patched the exploited software flaw and enforced mandatory password resets for affected users to mitigate potential risks of account hijacking. Additionally, KDDI's investigation confirmed that its own consumer email services, operating on a different infrastructure, were not compromised.
The compromised email platform is utilized by five ISPs: STNet, JCOM, Chubu Telecommunications C, NIFTY Corporation, and BIGLOBE. The security breach potentially affected both current and former customers' accounts, including some with inactive status. While many exposed passwords were stored in a secured format, details about encryption methods used were not fully disclosed.
This incident underlines the persistent challenges faced by telecom companies due to vulnerabilities in third-party software. The coordination between KDDI and the affected ISPs emphasizes the importance of collaborative security measures and highlights the necessity for ongoing vigilance and rapid response to zero-day threats to safeguard customer data.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
KDDI confirmed a June breach affected 12.2 million email addresses and 7.6 million passwords. A zero-day vulnerability was exploited, prompting urgent password resets for all compromised accounts.
KDDI announced that a data breach impacted over 12 million users, exposing email addresses and passwords via a compromised email platform used by multiple ISPs. The company is working to secure accounts and has implemented measures to prevent future incidents, highlighting the risks of zero-day vulnerabilities in third-party software.
KDDI reported that a cyberattack exposed 12.2 million email addresses and 7.6 million passwords linked to five ISPs. The breach stemmed from a vulnerability in third-party software, which KDDI has patched, ensuring its own services remained secure. This incident highlights ongoing security challenges for Japanese companies amid a rise in cyber incidents.