Japanese telecommunications giant KDDI Corporation has graced the cybersecurity world with yet another cautionary tale, disclosing a data breach in which threat actors successfully infiltrated one of its email systems — a system conveniently shared by five other internet service providers across Japan. Because why contain the damage when you can spread it?
The company reports it detected the intrusion on June 17, at which point it sprang into action with the kind of urgency one might expect from an organization with 45,000 employees and an annual revenue of $32.4 billion. The attackers, it turns out, exploited a vulnerability in an unnamed third-party software — because identifying the software responsible might, apparently, be asking too much.
The Anatomy of a Very Preventable Incident
KDDI's investigators determined that unauthorized parties may have obtained customer email addresses and passwords as a result of the breach. The company has been careful to use the phrase "there remains a possibility" — a masterclass in corporate understatement when up to 14.22 million accounts are potentially at risk.
The five ISP operators caught in KDDI's security umbrella include:
STNet, Inc.
JCOM Co., Ltd.
Chubu Telecommunications Co., Inc.
NIFTY Corporation
BIGLOBE Inc.
Current customers, former customers, and even inactive accounts were swept up in the exposure — because apparently, KDDI's data retention philosophy favors quantity over security
A Silver Lining — Sort Of
In a rare moment of good news, KDDI notes that some passwords were stored in hashed and/or encrypted form, meaning not every credential can be immediately weaponized for account takeovers. However, the company declined to specify what encryption standard was used, or what percentage of passwords were stored in plaintext — details that one might consider rather important, but which KDDI has chosen to leave as a delightful mystery for affected customers to ponder.
The Regulatory Notification Tour
Since June 17, KDDI has been busy notifying affected ISPs, Japan's Personal Information Protection Commission, and the Ministry of Internal Affairs and Communications — a thorough regulatory tour that, while commendable, does little to un-expose the millions of credentials already potentially in criminal hands.
The company assures the public that it is actively working with affected ISPs to implement "additional security measures" — which raises the obvious question of what the previous security measures were doing in the first place.
What You Should Do (Since KDDI Can't Do It For You)
If you are among the potentially 14.22 million affected customers, cybersecurity professionals — and basic common sense — recommend the following:
Reset your email account password immediately, and resist the temptation to use the same password you use everywhere else.
Enable two-factor authentication (2FA) if your provider supports it, which adds a layer of protection that no amount of unnamed third-party vulnerabilities can easily bypass.
KDDI's investigation remains ongoing. Customers are advised to stay tuned for further updates — and perhaps to lower their expectations accordingly.
KDDI Corporation has operated since 2000, following the merger of IDO, DDI, and KDD. In 25 years of operation, one might have hoped for slightly more robust email infrastructure. One would have been wrong.