Telco giant KDDI says data breach affects over 12 million people

A massive data breach affecting over 12 million people has been revealed by Japanese telecommunications giant KDDI, exposing email addresses and passwords used by customers of five internet service providers (ISPs) in the country. The incident highlights the importance of robust cybersecurity measures and the need for organizations to stay vigilant against attacks.

KDDI is one of Japan’s largest mobile telecommunications providers, with a significant presence in the country. The company revealed that attackers breached an email platform used by several ISPs, gaining access to sensitive information. In total, around 12 million email addresses were exposed, along with over 7 million passwords. While some passwords were stored in hashed and encrypted form, making them more secure, the exact number of accounts with plaintext passwords or the type of encryption used is unknown.

The breach is believed to have occurred on May 16, when attackers exploited a zero-day vulnerability in a third-party software. KDDI explained that the vulnerability was not recognized by the software vendor at the time, but has since been reported and is being addressed. The company has implemented defensive measures, including blocking the attackers’ access and deploying Endpoint Detection and Response (EDR) software to help detect future breach attempts.

The impact of this breach extends beyond KDDI’s customers, as the exposed information may be used for malicious purposes such as phishing or account hijacking. To mitigate these risks, KDDI is working with affected ISPs to implement security measures, including mandatory password changes for all users. Customers who regularly use email services have already been encouraged to change their passwords.

This incident serves as a reminder that cybersecurity threats are ever-present and can have far-reaching consequences. Organizations must prioritize robust security measures, including regular testing and vulnerability assessments, to stay ahead of potential attacks. By taking proactive steps to identify and address vulnerabilities, companies can reduce the risk of data breaches like this one.

As security teams struggle to keep pace with emerging threats, it’s essential to test all layers of security before attackers do. A recent whitepaper highlights the importance of breach and attack simulation in testing SIEM and EDR rules, ensuring that threats are not slipping through detection. In light of KDDI’s data breach, organizations should consider implementing similar measures to stay one step ahead of potential threats.

In conclusion, this incident underscores the importance of robust cybersecurity practices and the need for ongoing vigilance against emerging threats. As a precautionary measure, it’s essential to change passwords regularly and be cautious when receiving unsolicited emails or login requests. By staying informed and taking proactive steps, individuals can reduce their risk of falling victim to data breaches like this one.


Source: Bleeping Computer — 2026-07-08