Japanese telecom giant KDDI confirmed that a June data breach compromised 12.2 million email addresses and 7.6 million passwords. The attack targeted a third‑party system used by five ISPs, exploiting a zero‑day vulnerability before the company could patch it.

Japan’s leading telecommunications provider KDDI announced this week that a data breach on June 17 exposed the email addresses of over 12 million users and the passwords of 7.6 million individuals. The incident involved an unauthorized intrusion into a third‑party system that underpins the email infrastructure of five major ISPs – STNet, JCOM, Chubu Telecommunications, NIFTY, and BIGLOBE – while KDDI’s own mobile and fixed‑line email services, which run on separate infrastructure, remained untouched.

Technical Background

The attackers leveraged a zero‑day vulnerability in a piece of software integrated into the ISP email system. According to a translated KDDI notice, the flaw had been exploited by attackers since May, prompting the vendor to rush a patch. KDDI immediately removed the intruders from its networks and found no evidence of further suspicious activity.

User Impact and Company Response

In response, KDDI has partnered with the affected ISPs to enforce password resets. A mandatory reset will be completed for all compromised accounts in the coming days, and users who regularly use their email addresses have already updated their login credentials. The company is conducting a thorough audit of the implicated software to ensure no additional vulnerabilities remain and is working with ISPs to transition to more secure communication technologies.

Industry Implications

This breach underscores the critical importance of securing third‑party components within complex email infrastructures. Zero‑day exploits can remain hidden until they cause significant damage, and swift patching is essential to mitigate widespread data exposure. KDDI’s proactive response and collaboration with partners set a benchmark for incident containment in the telecommunications sector.

Future Directions

Moving forward, KDDI has pledged to strengthen its security posture and adopt more resilient communication frameworks. The incident will likely prompt telecom operators worldwide to re‑evaluate the risk of third‑party software and accelerate the adoption of robust security practices across their networks.