2026-06-29 · view entry permalink →
KDDI third-party email platform breach exposes up to 14.22 million credentials across six Japanese ISPs
Japanese carrier KDDI disclosed that a threat actor exploited a vulnerability in third-party software integrated into its centralised ISP email-management platform, with unauthorised access detected on approximately 2026-06-17 (BleepingComputer, 2026-06-28). The breach potentially exposed email addresses and passwords for up to 14.22 million subscriber accounts across six ISPs running on the shared platform, STNet, JCOM, Chubu Telecommunications, Nifty, Biglobe and a further KDDI ISP; KDDI states some passwords were stored hashed or encrypted and that 14.22 million is a worst-case figure pending forensic completion (SecurityAffairs, 2026-06-28; Infosecurity Magazine, 2026-06-24). No CVE for the third-party software flaw and no threat actor have been named; KDDI notified Japan's Personal Information Protection Commission and advised affected users to change passwords and enable MFA.
Why it matters to us: The structural lesson, not the jurisdiction, is the signal, a single vulnerable dependency in a shared multi-tenant email-management plane produced a six-ISP blast radius, the same exposure model any European telco or managed-ISP operator carries when subscriber-mail administration is consolidated onto one vendor platform. The immediate downstream risk for Swiss/EU defenders is credential-stuffing: 14.22 million leaked email/password pairs will surface in combolists and feed phishing-as-initial-access. Hunt for anomalous authentication against external-facing services from Japanese-ISP email address spaces, and treat any reused-password exposure on those domains as a stuffing precursor. Inventory third-party vendor access to your own subscriber/identity-management platforms and enforce MFA on the administration plane itself.
"As a result of our investigation, as of June 17, 2026, the date of our confirmation, this vulnerability was not recognized by the software vendor," KDDI said.
KDDI's 6 July update (reported by BleepingComputer on 8 July) discloses the confirmed root cause and exact scale of the breach of the shared email platform serving STNet, JCOM, Chubu Telecommunications, NIFTY and BIGLOBE. The platform was compromised on 16 May 2026 via a zero-day vulnerability in an (still unnamed) third-party software component, a flaw that, per KDDI, "was not recognized by the software vendor" as of KDDI's 17 June confirmation date and which the vendor is now reporting to public authorities (BleepingComputer, 2026-07-08). KDDI confirmed final counts of 12,233,087 exposed email addresses and 7,616,173 exposed passwords, down from the earlier "up to 14.22 million" estimate (BleepingComputer, 2026-06-28), deployed EDR post-incident, completed a forensic audit on 23 June confirming the flaw was patched with no other issues remaining, and notified Japan's Personal Information Protection Commission and the Ministry of Internal Affairs and Communications.
Neither report names the exploited third-party product; KDDI has stated only "third-party software", and that ambiguity is in the source, not omitted here.