All stories

Millions of user credentials leaked following zero-day exploit in KDDI email system

A zero-day vulnerability in KDDI's email system has exposed the credentials of millions of users across several Japanese ISPs. Attackers compromised 12.2 million email addresses and 7.6 million passwords. Defenders should monitor for unauthorized access to ISP-linked mail accounts and prepare for mandatory password resets.

Summary

Japanese telecommunications provider KDDI confirmed that a zero-sday vulnerability in its email infrastructure was exploited, impacting over 12 million individuals. The unauthorized access targeted a system developed by KDDI used by five different internet service providers (ISPs). While the breach involved significant credential theft, KDDI stated that its mobile and fixed-line internet services remain unaffected as they operate on separate infrastructure.

What happened

The incident was detected following unauthorized access to an email system on June 17. However, internal investigations suggest the exploitation of the zero-day vulnerability may have been active since May. The compromised data includes the email addresses of 12.2 million people and the passwords of 7.6 million individuals.

The attack specifically targeted a system used by five Japanese ISPs:

  • STNet
  • JCOM
  • Chubu Telecommunications
  • NIFTY
  • BIGLOBE

KDDI reported that it evicted the attackers from its systems immediately upon discovery and found no evidence of further suspicious activity within its environment.

Technical details

The breach originated from a zero-day vulnerability in software implemented as part of KDDI's email infrastructure. While the specific nature of the flaw has not been disclosed, the vendor is currently developing a patch to remediate the issue.

The scope of the impact is limited to the shared email system used by the aforementioned ISPs. Because the mobile and fixed-line internet services utilize different infrastructure, they were not subject to this exploit.

Why this matters for defenders

This incident highlights the risks associated with shared infrastructure in telecommunications. A single vulnerability in a centralized email system can have cascading effects across multiple service providers.

The scale of the credential theft-specifically the 7.6 million passwords-poses a significant risk of credential stuffing attacks against other services if users have reused these credentials.

Defender guidance

KDDI is currently managing the incident through several remediation steps:

  • Mandatory Password Resets: KDDI is working with affected ISPs to prompt password resets. While frequent users have already updated their information, a mandatory reset will be enforced for all affected accounts in the coming days.
  • Software Inspection: The company is conducting a thorough inspection of the involved software to identify any remaining vulnerabilities.
  • Infrastructure Transition: KDDI plans to work with its ISP partners to transition toward more secure communication technologies.

Organizations should monitor for unusual login attempts on email accounts associated with these ISPs and advise users to update credentials if they have been using the affected services.

Sources

  1. https://www.securityweek.com/12-million-impacted-by-data-breach-at-japanese-telco-kddi/
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -