Skip to content
Tech News
← Back to articles

Data breach exposes up to 14.2 million email logins at six ISPs

read original more articles
Why This Matters

A significant data breach at KDDI Corporation exposed up to 14.2 million email logins across multiple Japanese ISPs, highlighting vulnerabilities in third-party software and the importance of robust cybersecurity measures. The incident underscores the ongoing risks faced by large telecom providers and their customers, emphasizing the need for improved data protection and incident response strategies in the tech industry.

Key Takeaways

Japanese telecommunications operator KDDI Corporation disclosed a data breach where threat actors gained access to one of its email systems used by five other internet service providers (ISPs) in the country.

The company says that it discovered the compromise on June 17 and responded immediately by blocking the attacker and implementing defense measures.

The investigation determined that the hackers exploited a vulnerability in an unnamed third-party software that KDDI Corporation used on its system.

“Although technical defensive measures have already been implemented for the system, there remains a possibility that customers' email addresses and passwords were obtained by unauthorized third parties as a result of the incident,” KDDI warns.

Scale of exposure

KDDI is one of Japan’s largest ISPs, with 45,000 employees and an annual revenue of $32.4 billion. It is a public entity that has operated since 2000, following the merger of IDO, DDI, and KDD, Japan's former state-monopoly international telecommunications provider.

The company says that the incident impacted the following five ISP operators and their email services:

STNet, Inc. JCOM Co., Ltd. Chubu Telecommunications C., Inc. NIFTY Corporation BIGLOBE Inc.

Although the investigation into the incident is still underway and the exact number of impacted accounts has yet to be determined, KDDI said it may have exposed the email addresses and passwords of up to 14,22 million customers.

This figure includes current and former customers, as well as inactive accounts that may no longer be in use.

... continue reading