KDDI Zero-Day Exploit in Third-Party Software Exposes Up to 14.2 Million Email Accounts at Six Japanese ISPs (STNet, JCOM, Chubu Telecommunications, NIFTY, BIGLOBE, KDDI Web Communications)
KDDI Zero-Day Exploit in Third-Party Software Exposes Up to (TL-2026-1235), also tracked as KDDI ISP Email System Breach, is a high-severity data breach, first published 2026-07-11. It has no confirmed attribution, affects KDDI Corporation Shared ISP email infrastructure (third-party software, maps to 17 MITRE ATT&CK techniques (T1016, T1041, T1059), and is covered by 9 detection rules and 19 indicators of compromise.
Key facts for TL-2026-1235
- Threat ID
- TL-2026-1235
- Also known as
- KDDI ISP Email System Breach, KDDI Shared Mail Infrastructure Zero-Day
- Severity
- HIGH
- Status
- ACTIVE
- Category
- DATA_BREACH
- First published
- 2026-07-11
- Last reviewed
- 2026-07-11
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- telecoms, internet-service-providers, consumer-services
- Target regions
- japan, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 19
Threat actors exploited a zero-day vulnerability in unnamed third-party software embedded in a shared email infrastructure platform operated by Japanese telecom KDDI Corporation on behalf of six ISPs. Unauthorized access began around 2026-05-16 and was discovered 2026-06-17; KDDI has since confirmed 12,233,087 email addresses and 7,616,173 passwords (some hashed/encrypted, some reportedly stored in plaintext) were leaked, out of a worst-case exposure of up to 14.22 million current, former, and inactive customer accounts.
How KDDI Zero-Day Exploit in Third-Party Software Exposes Up to works
On 2026-06-17, KDDI Corporation detected unauthorized access to a shared email system it operates and provides to multiple internet service providers (ISPs) across Japan. Subsequent forensic investigation determined that the intrusion had actually begun as early as 2026-05-16, meaning attackers had roughly one month of undetected access to the platform before discovery. The root cause was identified as exploitation of a zero-day vulnerability in third-party software embedded in the shared mail infrastructure -- the flaw was unknown to the software vendor at the time of exploitation ('this vulnerability was not recognized by the software vendor'), and as of the most recent public reporting KDDI stated the vendor was still developing a patch.
The shared platform underpins email services for six operators: STNet, Inc.; JCOM Co., Ltd. (J:COM NET mail); Chubu Telecommunications Co., Inc. (marketed under the Commufa and Pikara brands); NIFTY Corporation (@nifty Mail); BIGLOBE Inc. (BIGLOBE Mail); and KDDI Web Communications' CPI rental-server mail service. KDDI's own primary mobile and fixed-line broadband email services run on separate infrastructure and were confirmed unaffected.
On the day of discovery, KDDI modified the system to block further unauthorized activity, identified the suspected point of intrusion, and implemented additional technical defensive measures, effectively evicting the attacker from the environment. KDDI publicly disclosed the incident on 2026-06-23, initially describing a worst-case exposure of up to 14.22 million email addresses and passwords (current, former, and inactive accounts combined) across the six affected ISPs. Passwords were reported as stored in hashed and/or encrypted form for most accounts, though follow-on reporting indicates that some passwords were stored in plaintext -- meaning the exposure includes both directly usable plaintext credentials and hashed/encrypted values of varying (undisclosed) strength.
As the investigation progressed, KDDI narrowed the confirmed-impact figures: by 2026-07-06 the company confirmed that 12,233,087 email addresses had definitively been exfiltrated, of which 7,616,173 also had associated passwords confirmed leaked. KDDI notified Japan's Personal Information Protection Commission and the Ministry of Internal Affairs and Communications in line with regulatory breach-notification obligations, and coordinated with all six affected ISPs on customer notification and mandatory/recommended password resets. Affected users were advised to change their email passwords immediately and to enable two-factor authentication where the mail service supports it.
No threat actor has been publicly attributed to the intrusion, no CVE identifier has been assigned or disclosed for the exploited third-party software flaw, and no indicators of compromise (IPs, domains, malware hashes) tied to the intrusion have been published by KDDI or any of the reporting outlets as of this writing. Reporting is consistent that attacker post-exploitation behavior details (persistence mechanism, lateral movement, exfiltration channel/protocol) were not disclosed by KDDI beyond confirming that bulk email address/password pairs were accessed and exfiltrated from the shared backend. The case is illustrative of third-party/shared-infrastructure supply-chain risk in the Japanese telecom/ISP sector: a single vulnerable software component embedded in a shared platform produced a blast radius spanning six independently branded ISP mail services and up to 14.2 million subscriber accounts, with mixed plaintext/hashed password storage compounding downstream credential-stuffing risk.
MITRE ATT&CK techniques used in TL-2026-1235
Discovery
T1016 System Network Configuration Discovery; T1082 System Information Discovery
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Execution
T1059 Command and Scripting Interpreter
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Command and Control
T1071 Application Layer Protocol
Collection
T1074 Data Staged; T1213 Data from Information Repositories
Initial Access
T1190 Exploit Public-Facing Application
Defense Evasion
T1211 Exploitation for Stealth
Credential Access
T1212 Exploitation for Credential Access; T1552 Unsecured Credentials
Persistence
T1505 Server Software Component
Impact
Resource Development
Reconnaissance
Affected products and versions in KDDI Zero-Day Exploit in Third-Party Software Exposes Up to
- KDDI Corporation — Shared ISP email infrastructure (third-party software component, name undisclosed)
Vulnerable versions: Unspecified version in production as of May-June 2026
Fixed in: Patch in development, not yet released as of latest reporting - STNet, Inc. — STNet email service
Vulnerable versions: N/A - shared backend - JCOM Co., Ltd. — J:COM NET mail service
Vulnerable versions: N/A - shared backend - Chubu Telecommunications Co., Inc. — Commufa / Pikara mail services
Vulnerable versions: N/A - shared backend - NIFTY Corporation — @nifty Mail
Vulnerable versions: N/A - shared backend - BIGLOBE Inc. — BIGLOBE Mail
Vulnerable versions: N/A - shared backend - KDDI Web Communications Co., Ltd. — CPI rental server mail service
Vulnerable versions: N/A - shared backend
Remediation for KDDI Zero-Day Exploit in Third-Party Software Exposes Up to
Patches
- Vendor patch for the exploited zero-day in the unnamed third-party software was still in development as of the most recent public reporting; no patch version identifier has been published
Immediate actions
- Force password resets for all affected customer accounts across STNet, JCOM, Chubu Telecommunications, NIFTY, BIGLOBE, and KDDI Web Communications CPI mail
- Enable two-factor authentication on affected webmail accounts where supported
- Monitor affected accounts for credential-stuffing and password-reuse attacks on other services
- Treat exposed email/password pairs as compromised across any service where the same credentials were reused
- Prioritize remediation for accounts whose passwords were stored in plaintext, since those credentials are immediately and directly usable by attackers without cracking
Workarounds
- KDDI applied compensating technical defensive measures and blocked the identified intrusion vector pending a vendor patch
Longer-term hardening
- Complete vendor patch deployment for the exploited third-party software once available
- Conduct comprehensive security review of all third-party software components embedded in shared multi-tenant infrastructure
- Segment shared ISP email infrastructure to reduce single-point blast radius across multiple ISP brands
- Migrate to stronger password hashing/storage technology as referenced in KDDI's stated plan to move to 'more secure communication technologies'; eliminate any remaining plaintext password storage
- Implement enhanced logging/detection on shared infrastructure to reduce dwell time (current confirmed dwell time was approximately one month)
Timeline of KDDI Zero-Day Exploit in Third-Party Software Exposes Up to
- Threat actor gains unauthorized access to KDDI's shared ISP email infrastructure via a zero-day vulnerability in third-party software; access goes undetected for roughly one month.
- KDDI detects the intrusion, blocks the attacker, identifies the suspected point of unauthorized access, and implements technical defensive measures, effectively evicting the attacker the same day.
- KDDI internally confirms that email addresses and passwords used for the affected mail service may have been leaked externally.
- KDDI Web Communications publishes its own incident notice confirming unauthorized access to its mail service and the CPI rental-server platform.
- KDDI publicly discloses the breach, notifying that up to 14.22 million current, former, and inactive customer accounts across six ISPs (STNet, JCOM, Chubu Telecommunications, NIFTY, BIGLOBE, KDDI Web Communications) may be affected; regulators are notified.
- The Japan Times and other outlets report on the disclosed breach and its scale, citing up to 14 million potentially affected accounts.
- Japanese IT trade press (@IT/atmarkit) reports on the unauthorized access to KDDI's ISP email system, citing the 14.22 million worst-case figure.
- Continued English-language media coverage characterizes the incident as a shared-infrastructure flaw impacting six ISPs.
- Follow-on reporting (SecurityWeek, Security Boulevard, BleepingComputer) confirms the root cause as a zero-day exploit in third-party software unrecognized by the vendor at exploitation time, with a vendor patch still in development, and notes that some exposed passwords were stored in plaintext rather than hashed/encrypted.
- KDDI confirms definitive impact numbers: 12,233,087 email addresses leaked, of which 7,616,173 also had passwords confirmed leaked, refining the initial worst-case estimate of 14.22 million.
Sources cited for KDDI Zero-Day Exploit in Third-Party Software Exposes Up to
- Data breach exposes up to 14.2 million email logins at six ISPs
- Japanese telecom giant KDDI says data breach affects 12 million people
- 12 Million Impacted by Data Breach at Japanese Telco KDDI
- KDDI Data Breach Impacts up to 14.2 Million Email Accounts at Six ISPs
- KDDI Confirms Zero-Day Exploit Behind Breach Affecting 12 Million People
- Information for 14 million email accounts possibly leaked in cyberattack on KDDI
- 当社メールサービスに対する不正アクセスの発生について - 株式会社KDDIウェブコミュニケーションズ
- 2026年6月23日<報道発表資料>KDDI株式会社 ISP事業者向けメールシステムに対する不正アクセスの発生について
- KDDIのメールシステムに不正アクセス 最大1422万件情報漏えいの恐れ
- 【セキュリティ ニュース】KDDIのISP向けメールシステム侵害
- KDDI、メールシステムへの不正アクセスで1,223万件のメールアドレスが漏洩、パスワードは761万件 漏洩
- KDDI Data Breach Exposes 14.2 Million Logins: Shared Infrastructure Flaw Hits Six ISPs
Threats related to KDDI Zero-Day Exploit in Third-Party Software Exposes Up to
- OpenAI AI Agents Autonomously Escape Sandbox, Exploit Zero-Days, Compromise Hugging Face Production Infrastructure
- Broken Object-Level Authorization (BOLA) in Airline GraphQL Booking API Exploited via Autonomous AI Red-Team Agent
- CVE-2026-66066 "KindaRails2Shell": Critical Ruby on Rails Active Storage Flaw Allows Unauthenticated Arbitrary File Read / RCE via libvips Image Processing
- Alleged Starbucks Data Breach — Threat Actor 'anes2010' Claims 176M Customer Records for Sale on Cybercrime Forum
- Snowflake GitHub Actions Workflow Injection Exposes Internal Jira Credentials
Detection coverage for TL-2026-1235
As of 2026-07-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1235 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.