ctipilot.ch

KDDI email-platform breach

incident · incident:kddi-isp-email-platform-breach-2026 single-source

KDDI third-party email-platform breach exposes up to 14.22M credentials across six Japanese ISPs.

Coverage timeline
2
first 2026-06-29 → last 2026-07-12
Peak priority
notable
1 notable · 1 routine
Sources cited
7
5 hosts
Sections touched
2
updates, weekly-incidents-recap
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
4
pinned v19.2 · see below
2026-07-092 appearances2026-07-12

ATT&CK techniques

4 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-12/weekly-w28-third-party-cloud-account-exposure · ATT&CK page ↗

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-07-12/weekly-w28-third-party-cloud-account-exposure · ATT&CK page ↗

T1199Trusted Relationship×1

Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.

Evidence: 2026-07-12/weekly-w28-third-party-cloud-account-exposure · ATT&CK page ↗

Persistence TA0003

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-12/weekly-w28-third-party-cloud-account-exposure · ATT&CK page ↗

Privilege Escalation TA0004

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-12/weekly-w28-third-party-cloud-account-exposure · ATT&CK page ↗

Stealth TA0005

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-12/weekly-w28-third-party-cloud-account-exposure · ATT&CK page ↗

Exfiltration TA0010

T1567Exfiltration Over Web Service×1

Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.

Evidence: 2026-07-12/weekly-w28-third-party-cloud-account-exposure · ATT&CK page ↗

Story timeline

  1. 2026-07-12This week's disclosures clustered on third-party, cloud-account and vendor exposure — the breach rarely started inside the victim
    weekly-incidents-recapW28 incidents cluster on third-party / cloud-account exposure — Accenture, Deutsche Bank vendor, KDDI, Nayax cloud account, Odido vishing, Nextcloud misconfig
  2. 2026-07-09KDDI names the root cause of its ISP email-platform breach: a zero-day in third-party software the vendor had not recognized
    updatesKDDI pins its multi-ISP email-platform breach on a zero-day in an unnamed third-party component the vendor had not recognised

Where this entity is cited

  • updates1
  • weekly-incidents-recap1

Source distribution

  • bleepingcomputer.com3 (43%)
  • computing.co.uk1 (14%)
  • cybernews.com1 (14%)
  • politie.nl1 (14%)
  • sec.gov1 (14%)

explore in graph

Entries about KDDI email-platform breach (2)

2026-07-12 · view entry permalink →

NOTABLENATOB1

This week's disclosures clustered on third-party, cloud-account and vendor exposure — the breach rarely started inside the victim

Read as a set, the week's confirmed incidents point away from the classic perimeter-RCE story and toward exposure that lives in someone else's account, platform or supply chain.

The third-party / vendor strand: Accenture confirmed a data-theft incident after the handle "888" advertised roughly 35 GB of internal source code (BleepingComputer, 2026-07-08); Deutsche Bank disclosed a third-party-vendor incident after the "Unsafe" ransomware group posted claims (Computing, 2026-07-09); and KDDI named a zero-day in third-party email-platform software as the root cause of a breach affecting about 12 million people (BleepingComputer, 2026-07-09). The cloud-account strand: Nayax, a Bank-of-Lithuania-licensed EEA payment institution, disclosed a cloud-account incident (claimed by "The Syndicate") in its own SEC Form 6-K (Nayax, 2026-07-09); ShinyHunters' Odido (Netherlands telecom) breach drew a Dutch-national-involvement assessment from police voice analysis (Politie, 2026-07-08); and Nextcloud GmbH's own hosting infrastructure exposed roughly 367,000 internal records through a misconfigured public Elasticsearch (Cybernews, 2026-07-10).

Why the pattern matters for the constituency: several victims are directly relevant classes — an EEA-licensed payment institution, an EU telecom, a European cloud vendor — and the shared root cause is exactly the exposure a Swiss/EU public-sector or CI organisation inherits through its suppliers and cloud tenancy. The transferable lesson is that a mature internal patch posture does not cover a vendor's zero-day, a supplier's compromised account, or a misconfigured datastore in your own cloud footprint.

Builds on: 2026-07-08/accenture-confirms-data-theft-888-azure-devops-claim · 2026-07-09/deutsche-bank-unsafe-ransomware-third-party-vendor-incident · 2026-07-09/kddi-isp-email-breach-zero-day-root-cause-update · 2026-07-09/nayax-cloud-account-incident-the-syndicate-claim · 2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution · 2026-07-10/nextcloud-gmbh-elasticsearch-exposure-msb-nrw

incident12 Jul 23:34Zmulti-sourceOpen finding ↗

2026-07-09 · view entry permalink →

ROUTINEupdateNATOB2

KDDI names the root cause of its ISP email-platform breach: a zero-day in third-party software the vendor had not recognized

UPDATE · originally covered KDDI third-party email platform breach exposes up to 14.22 million credentials across six Japanese ISPs (2026-06-29)

KDDI's 6 July update — reported by BleepingComputer on 8 July — discloses the confirmed root cause and exact scale of the breach of the shared email platform serving STNet, JCOM, Chubu Telecommunications, NIFTY and BIGLOBE. The platform was compromised on 16 May 2026 via a zero-day vulnerability in an (still unnamed) third-party software component — a flaw that, per KDDI, "was not recognized by the software vendor" as of KDDI's 17 June confirmation date and which the vendor is now reporting to public authorities (BleepingComputer, 2026-07-08). KDDI confirmed final counts of 12,233,087 exposed email addresses and 7,616,173 exposed passwords — down from the earlier "up to 14.22 million" estimate (BleepingComputer, 2026-06-28) — deployed EDR post-incident, completed a forensic audit on 23 June confirming the flaw was patched with no other issues remaining, and notified Japan's Personal Information Protection Commission and the Ministry of Internal Affairs and Communications.

Neither report names the exploited third-party product; KDDI has stated only "third-party software", and that ambiguity is in the source, not omitted here.

"As a result of our investigation, as of June 17, 2026, the date of our confirmation, this vulnerability was not recognized by the software vendor," KDDI said.

KDDI (via BleepingComputer)
incident09 Jul 12:38Zsingle-sourceOpen finding ↗