KDDI Breach Exposes 12.2M Emails, 7.6M Passwords
KDDI confirmed a June 17 breach that exposed 12.2 million email addresses and 7.6 million passwords from an email system used by five internet service providers.
KDDI confirmed that an unauthorized intrusion on June 17 exposed the email addresses of 12.2 million users and the passwords of 7.6 million. The breach affected a system KDDI built to support email services for multiple internet service providers.
The affected ISPs are STNet, JCOM, Chubu Telecommunications, NIFTY and BIGLOBE. KDDI’s mobile and fixed-line internet email services run on separate infrastructure and were not impacted by the incident.
Company notices indicate attackers exploited a zero-day vulnerability in software that is part of the shared email system. The software vendor is developing a patch and KDDI has said it will inspect the component for other potential flaws.
KDDI reports evidence that some ISPs may have been exposed to exploit activity since May. The intrusion was discovered on June 17, and KDDI removed the intruders from its systems immediately after detection. Investigators have found no evidence of additional suspicious activity so far.
KDDI coordinated with the affected ISPs to prompt password resets for compromised accounts. The company reported many regular users have already updated their login details and that a mandatory password reset for all affected accounts will be completed in the coming days.
The telecom also plans to work with the ISPs to migrate to stronger communication technologies for the affected services. KDDI notified customers of the breach, the planned forced password resets and said it will continue investigating the scope of the incident in cooperation with the ISPs and the software vendor.








