Japanese telecommunications giant KDDI Corporation disclosed on June 23 that attackers exploited a vulnerability in third-party software to breach a shared email platform it operates on behalf of six internet service providers, potentially exposing login credentials for up to 14.22 million accounts. The affected services include STNet, KDDI Web Communications, JCOM, Chubu Telecommunications, Nifty, and BIGLOBE.
KDDI detected the unauthorized access on June 17 and responded by blocking the attacker and implementing defensive measures. The company notified Japan’s Personal Information Protection Commission and the Ministry of Internal Affairs and Communications. The exposed data includes email addresses and passwords across current, former, and inactive accounts.
The breach highlights a structural risk in telecommunications infrastructure where a single operator manages email services for multiple branded ISPs on shared backend systems. A vulnerability in one third-party component propagates across all tenants simultaneously. The unnamed third-party software that provided the attack vector represents the supply chain dependency pattern that CISA and ENISA have repeatedly flagged as a systemic concern for critical infrastructure operators.
For enterprise security teams operating in markets with similar shared-infrastructure telecom models, the incident reinforces the need to treat ISP-provided email as a low-assurance channel and to ensure that critical accounts are not tied to credentials that depend on a third-party email provider’s security posture.
Source: BleepingComputer.