A massive data breach at Japanese telecom giant KDDI has compromised the personal information of over 12 million people. The incident occurred on June 17 when hackers exploited a zero-day vulnerability in software used by five internet service providers (ISPs) that are customers of KDDI.
The affected ISPs, which include STNet, JCOM, Chubu Telecommunications, NIFTY, and BIGLOBE, use an email infrastructure developed by KDDI. However, it’s worth noting that the mobile and fixed-line internet email services provided by these ISPs were not affected by the attack. The breach only compromised the email accounts used for ISP business purposes.
According to a statement from KDDI, hackers exploited a zero-day vulnerability in software implemented as part of the email infrastructure system. This means that the exploit was unknown to the vendor at the time it occurred, and no patch or fix was available to prevent the attack. The notice also indicates that several ISPs have been affected by the bug’s exploitation since May.
In this breach, hackers accessed the email addresses of 12.2 million people and the passwords of 7.6 million individuals. KDDI has stated that it has been working with the affected ISPs to prompt password resets for customers who use their email accounts regularly. Additionally, a mandatory password reset will be completed for all affected email accounts within the coming days.
KDDI claims to have taken swift action in responding to the breach, evicting the hackers from its systems immediately after discovering the incident and finding no evidence of additional suspicious activity. The company has also announced that it will thoroughly inspect the involved software to ensure there are no other vulnerabilities present and collaborate with the ISPs to transition to more secure communication technologies.
The KDDI data breach serves as a stark reminder of the importance of security in the digital age. As we become increasingly reliant on technology, our personal information is constantly at risk. It’s essential for organizations to prioritize cybersecurity measures and stay vigilant against emerging threats.
As consumers, it’s crucial that we take proactive steps to protect ourselves from potential data breaches. This includes being cautious when using public Wi-Fi networks, avoiding suspicious emails or links, and keeping software up-to-date with the latest security patches. By staying informed and taking preventative measures, we can minimize our risk of falling victim to a data breach.
KDDI’s handling of this incident demonstrates that swift action and transparency are crucial in responding to data breaches. As we move forward, it will be interesting to see how organizations adapt their cybersecurity strategies to prevent similar incidents from occurring in the future.
Source: SecurityWeek — 2026-07-09