KDDI, Japan’s second-largest mobile carrier, confirmed a data breach affecting over 12 million people. Attackers got email addresses and passwords after breaking into an email platform used by five ISPs under the KDDI umbrella.
The company discovered the breach on June 17 and says they blocked access and deployed defensive measures. But the damage was already done.
Here’s the timeline: attackers breached the platform on May 16 by exploiting a zero-day vulnerability in third-party software. KDDI says that as of June 17, the software vendor didn’t even know about the flaw yet. The vendor has since reported it to authorities and is working on disclosure.
The numbers are ugly. Email addresses of 12,233,087 people exposed. Passwords of 7,616,173 others. Some passwords were hashed or encrypted — KDDI didn’t say how many were stored in plaintext or what encryption was used.
The ISPs affected include STNet, JCOM, Chubu Telecommunications, NIFTY Corporation, and BIGLOBE. KDDI is forcing password changes across the board, prioritizing active users first, with mandatory resets for inactive accounts within one to two days.
They’ve also deployed EDR software since the attack and a forensic audit on June 23 confirmed the vulnerability is patched and no other issues remain. Japan’s Personal Information Protection Commission and the Ministry of Internal Affairs have been notified.
KDDI operates with 45,000 employees and $32.4 billion in annual revenue. A breach of this scale at a company that size is a reminder that zero-days don’t discriminate. And if you’re one of those 12 million people, change your password yesterday.
