14.2 Million Email Logins Exposed Across Six Japanese ISPs
KDDI Corporation, one of Japan's largest telecoms operators, has confirmed a breach of its email systems affecting up to 14.22 million accounts across five partner ISPs, according to Bleeping Computer.
The attackers got in by exploiting a vulnerability in unnamed third-party software running on KDDI's email platform. Once inside, they had potential access to email addresses and passwords belonging to customers of STNet, JCOM, Chubu Telecommunications, NIFTY Corporation, and BIGLOBE — past and present. Inactive accounts were also caught in the net.
KDDI discovered the intrusion on June 17 and moved quickly to block the attacker and notify Japan's Personal Information Protection Commission and the Ministry of Internal Affairs and Communications. The investigation is still ongoing.
There is some partial good news: a portion of passwords were stored in hashed or encrypted form, which adds a layer of protection even if the data was lifted. The problem is KDDI has not confirmed what percentage were stored that way, nor the strength of the encryption used. Some may have been stored in plaintext. That is the kind of vagueness that should worry you.
What the attacker wanted is not difficult to guess. Fresh email credentials are valuable for account takeovers, spam campaigns, and credential stuffing (where stolen username and password pairs are tried automatically across other services — think banking, shopping, anything you reuse that password on).
What you should do: If you are a customer of STNet, JCOM, Chubu Telecommunications, NIFTY, or BIGLOBE, reset your email password now. Then check every account where you used that same password and change those too. Enable two-factor authentication (2FA) on your email if it is available — it means a stolen password alone is no longer enough to break in.
Sources

