Japanese telecom giant KDDI confirmed that over 12 million people had their data stolen in a June breach. Hackers exploited a zero-day vulnerability in a third-party system to access an email infrastructure used by five ISPs.
The incident went down on June 17. The attackers got into a system KDDI built as part of the email backend for STNet, JCOM, Chubu Telecommunications, NIFTY, and BIGLOBE. KDDI’s own mobile and fixed-line email services run on separate infrastructure and weren’t touched.
Here’s what was taken: email addresses for 12.2 million people and passwords for 7.6 million. The vendor behind the exploited software is working on a patch now.
KDDI says it kicked the hackers out as soon as it found the breach and hasn’t seen any more suspicious activity since. They’ve been working with the affected ISPs to push password resets — some customers have already updated their credentials. A mandatory reset for all affected accounts is coming in the next few days.
The company says it will thoroughly inspect the vulnerable software for any other holes and help the ISPs move to more secure communication technologies.
This is another reminder that third-party software can be the weak link. A single zero-day in an email system component was enough to compromise millions of accounts.
