CTIPilot

KDDI email-platform breach

incident · incident:kddi-isp-email-platform-breach-2026

KDDI third-party email-platform breach exposes up to 14.22M credentials across six Japanese ISPs.

Coverage timeline
1
first 2026-06-29 → last 2026-06-29
Peak priority
high
1 high
Sources cited
4
3 hosts
Sections touched
1
active-threats
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
0
no mapped behavior yet

Story timeline

  1. 2026-06-29KDDI third-party email platform breach exposes up to 14.22 million credentials across six Japanese ISPs
    active-threats

Where this entity is cited

  • active-threats1

Source distribution

  • bleepingcomputer.com2 (50%)
  • infosecurity-magazine.com1 (25%)
  • securityaffairs.com1 (25%)

explore in graph

Entries about KDDI email-platform breach (1)

2026-06-29 · view entry permalink →

HIGHupdated

KDDI third-party email platform breach exposes up to 14.22 million credentials across six Japanese ISPs

Japanese carrier KDDI disclosed that a threat actor exploited a vulnerability in third-party software integrated into its centralised ISP email-management platform, with unauthorised access detected on approximately 2026-06-17 (BleepingComputer, 2026-06-28). The breach potentially exposed email addresses and passwords for up to 14.22 million subscriber accounts across six ISPs running on the shared platform, STNet, JCOM, Chubu Telecommunications, Nifty, Biglobe and a further KDDI ISP; KDDI states some passwords were stored hashed or encrypted and that 14.22 million is a worst-case figure pending forensic completion (SecurityAffairs, 2026-06-28; Infosecurity Magazine, 2026-06-24). No CVE for the third-party software flaw and no threat actor have been named; KDDI notified Japan's Personal Information Protection Commission and advised affected users to change passwords and enable MFA.

Why it matters to us: The structural lesson, not the jurisdiction, is the signal, a single vulnerable dependency in a shared multi-tenant email-management plane produced a six-ISP blast radius, the same exposure model any European telco or managed-ISP operator carries when subscriber-mail administration is consolidated onto one vendor platform. The immediate downstream risk for Swiss/EU defenders is credential-stuffing: 14.22 million leaked email/password pairs will surface in combolists and feed phishing-as-initial-access. Hunt for anomalous authentication against external-facing services from Japanese-ISP email address spaces, and treat any reused-password exposure on those domains as a stuffing precursor. Inventory third-party vendor access to your own subscriber/identity-management platforms and enforce MFA on the administration plane itself.

"As a result of our investigation, as of June 17, 2026, the date of our confirmation, this vulnerability was not recognized by the software vendor," KDDI said.

KDDI (via BleepingComputer)
Updaterun 2026-07-09T1211Z-intelactionsentitiesevidencesourcestagsbody

KDDI's 6 July update (reported by BleepingComputer on 8 July) discloses the confirmed root cause and exact scale of the breach of the shared email platform serving STNet, JCOM, Chubu Telecommunications, NIFTY and BIGLOBE. The platform was compromised on 16 May 2026 via a zero-day vulnerability in an (still unnamed) third-party software component, a flaw that, per KDDI, "was not recognized by the software vendor" as of KDDI's 17 June confirmation date and which the vendor is now reporting to public authorities (BleepingComputer, 2026-07-08). KDDI confirmed final counts of 12,233,087 exposed email addresses and 7,616,173 exposed passwords, down from the earlier "up to 14.22 million" estimate (BleepingComputer, 2026-06-28), deployed EDR post-incident, completed a forensic audit on 23 June confirming the flaw was patched with no other issues remaining, and notified Japan's Personal Information Protection Commission and the Ministry of Internal Affairs and Communications.

Neither report names the exploited third-party product; KDDI has stated only "third-party software", and that ambiguity is in the source, not omitted here.

incident29 Jun 04:47Zmulti-sourceOpen finding ↗