KDDI Email Platform Breach Exposes Millions of Customers
Japan's second-largest mobile carrier, KDDI, has confirmed a breach affecting customers across five internet service providers, according to Bleeping Computer.
Attackers got into a shared email platform on May 16 by exploiting a zero-day vulnerability (a security flaw unknown to the software vendor at the time of attack) in third-party software. The intrusion went undetected for a month. KDDI discovered it on June 17.
The numbers: 12.2 million email addresses and 7.6 million passwords were exposed across current and former customers of STNet, JCOM, Chubu Telecommunications, NIFTY Corporation, and BIGLOBE. Some passwords were stored in hashed or encrypted form, which makes them harder to misuse. KDDI has not confirmed how many were stored in plaintext.
Attackers with your email address and password can try that same combination across dozens of other services. Think of it like someone copying a key to your front door and then testing it on every flat in your building.
KDDI has since deployed EDR (Endpoint Detection and Response) software to catch future intrusions and has mandated forced password resets through affected ISPs.
What to do: If you use any of these ISPs — or if you reuse passwords anywhere — change those passwords now. Use a password manager to generate unique ones for each account. Enable two-factor authentication on your email wherever possible.
Sources

