KDDI Zero-Day Exploit in Third-Party Software Exposes Up to 14.2 Million Email Accounts at Six Japanese ISPs (STNet, JCOM, Chubu Telecommunications, NIFTY, BIGLOBE, KDDI Web Communications)

KDDI Zero-Day Exploit in Third-Party Software Exposes Up to (TL-2026-1235), also tracked as KDDI ISP Email System Breach, is a high-severity data breach, first published 2026-07-11. It has no confirmed attribution, affects KDDI Corporation Shared ISP email infrastructure (third-party software, maps to 17 MITRE ATT&CK techniques (T1016, T1041, T1059), and is covered by 9 detection rules and 19 indicators of compromise.

Key facts for TL-2026-1235

Threat ID
TL-2026-1235
Also known as
KDDI ISP Email System Breach, KDDI Shared Mail Infrastructure Zero-Day
Severity
HIGH
Status
ACTIVE
Category
DATA_BREACH
First published
2026-07-11
Last reviewed
2026-07-11
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
telecoms, internet-service-providers, consumer-services
Target regions
japan, Asia-Pacific
Detection rules
9
Indicators of compromise
19

Threat actors exploited a zero-day vulnerability in unnamed third-party software embedded in a shared email infrastructure platform operated by Japanese telecom KDDI Corporation on behalf of six ISPs. Unauthorized access began around 2026-05-16 and was discovered 2026-06-17; KDDI has since confirmed 12,233,087 email addresses and 7,616,173 passwords (some hashed/encrypted, some reportedly stored in plaintext) were leaked, out of a worst-case exposure of up to 14.22 million current, former, and inactive customer accounts.

How KDDI Zero-Day Exploit in Third-Party Software Exposes Up to works

On 2026-06-17, KDDI Corporation detected unauthorized access to a shared email system it operates and provides to multiple internet service providers (ISPs) across Japan. Subsequent forensic investigation determined that the intrusion had actually begun as early as 2026-05-16, meaning attackers had roughly one month of undetected access to the platform before discovery. The root cause was identified as exploitation of a zero-day vulnerability in third-party software embedded in the shared mail infrastructure -- the flaw was unknown to the software vendor at the time of exploitation ('this vulnerability was not recognized by the software vendor'), and as of the most recent public reporting KDDI stated the vendor was still developing a patch.

The shared platform underpins email services for six operators: STNet, Inc.; JCOM Co., Ltd. (J:COM NET mail); Chubu Telecommunications Co., Inc. (marketed under the Commufa and Pikara brands); NIFTY Corporation (@nifty Mail); BIGLOBE Inc. (BIGLOBE Mail); and KDDI Web Communications' CPI rental-server mail service. KDDI's own primary mobile and fixed-line broadband email services run on separate infrastructure and were confirmed unaffected.

On the day of discovery, KDDI modified the system to block further unauthorized activity, identified the suspected point of intrusion, and implemented additional technical defensive measures, effectively evicting the attacker from the environment. KDDI publicly disclosed the incident on 2026-06-23, initially describing a worst-case exposure of up to 14.22 million email addresses and passwords (current, former, and inactive accounts combined) across the six affected ISPs. Passwords were reported as stored in hashed and/or encrypted form for most accounts, though follow-on reporting indicates that some passwords were stored in plaintext -- meaning the exposure includes both directly usable plaintext credentials and hashed/encrypted values of varying (undisclosed) strength.

As the investigation progressed, KDDI narrowed the confirmed-impact figures: by 2026-07-06 the company confirmed that 12,233,087 email addresses had definitively been exfiltrated, of which 7,616,173 also had associated passwords confirmed leaked. KDDI notified Japan's Personal Information Protection Commission and the Ministry of Internal Affairs and Communications in line with regulatory breach-notification obligations, and coordinated with all six affected ISPs on customer notification and mandatory/recommended password resets. Affected users were advised to change their email passwords immediately and to enable two-factor authentication where the mail service supports it.

No threat actor has been publicly attributed to the intrusion, no CVE identifier has been assigned or disclosed for the exploited third-party software flaw, and no indicators of compromise (IPs, domains, malware hashes) tied to the intrusion have been published by KDDI or any of the reporting outlets as of this writing. Reporting is consistent that attacker post-exploitation behavior details (persistence mechanism, lateral movement, exfiltration channel/protocol) were not disclosed by KDDI beyond confirming that bulk email address/password pairs were accessed and exfiltrated from the shared backend. The case is illustrative of third-party/shared-infrastructure supply-chain risk in the Japanese telecom/ISP sector: a single vulnerable software component embedded in a shared platform produced a blast radius spanning six independently branded ISP mail services and up to 14.2 million subscriber accounts, with mixed plaintext/hashed password storage compounding downstream credential-stuffing risk.

MITRE ATT&CK techniques used in TL-2026-1235

Discovery

T1016 System Network Configuration Discovery; T1082 System Information Discovery

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Execution

T1059 Command and Scripting Interpreter

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Command and Control

T1071 Application Layer Protocol

Collection

T1074 Data Staged; T1213 Data from Information Repositories

Initial Access

T1190 Exploit Public-Facing Application

Defense Evasion

T1211 Exploitation for Stealth

Credential Access

T1212 Exploitation for Credential Access; T1552 Unsecured Credentials

Persistence

T1505 Server Software Component

Impact

T1531 Account Access Removal

Resource Development

T1588 Obtain Capabilities

Reconnaissance

T1594 Search Victim-Owned Websites

Affected products and versions in KDDI Zero-Day Exploit in Third-Party Software Exposes Up to

  • KDDI Corporation — Shared ISP email infrastructure (third-party software component, name undisclosed)
    Vulnerable versions: Unspecified version in production as of May-June 2026
    Fixed in: Patch in development, not yet released as of latest reporting
  • STNet, Inc. — STNet email service
    Vulnerable versions: N/A - shared backend
  • JCOM Co., Ltd. — J:COM NET mail service
    Vulnerable versions: N/A - shared backend
  • Chubu Telecommunications Co., Inc. — Commufa / Pikara mail services
    Vulnerable versions: N/A - shared backend
  • NIFTY Corporation — @nifty Mail
    Vulnerable versions: N/A - shared backend
  • BIGLOBE Inc. — BIGLOBE Mail
    Vulnerable versions: N/A - shared backend
  • KDDI Web Communications Co., Ltd. — CPI rental server mail service
    Vulnerable versions: N/A - shared backend

Remediation for KDDI Zero-Day Exploit in Third-Party Software Exposes Up to

Patches

  • Vendor patch for the exploited zero-day in the unnamed third-party software was still in development as of the most recent public reporting; no patch version identifier has been published

Immediate actions

  • Force password resets for all affected customer accounts across STNet, JCOM, Chubu Telecommunications, NIFTY, BIGLOBE, and KDDI Web Communications CPI mail
  • Enable two-factor authentication on affected webmail accounts where supported
  • Monitor affected accounts for credential-stuffing and password-reuse attacks on other services
  • Treat exposed email/password pairs as compromised across any service where the same credentials were reused
  • Prioritize remediation for accounts whose passwords were stored in plaintext, since those credentials are immediately and directly usable by attackers without cracking

Workarounds

  • KDDI applied compensating technical defensive measures and blocked the identified intrusion vector pending a vendor patch

Longer-term hardening

  • Complete vendor patch deployment for the exploited third-party software once available
  • Conduct comprehensive security review of all third-party software components embedded in shared multi-tenant infrastructure
  • Segment shared ISP email infrastructure to reduce single-point blast radius across multiple ISP brands
  • Migrate to stronger password hashing/storage technology as referenced in KDDI's stated plan to move to 'more secure communication technologies'; eliminate any remaining plaintext password storage
  • Implement enhanced logging/detection on shared infrastructure to reduce dwell time (current confirmed dwell time was approximately one month)

Timeline of KDDI Zero-Day Exploit in Third-Party Software Exposes Up to

  • Threat actor gains unauthorized access to KDDI's shared ISP email infrastructure via a zero-day vulnerability in third-party software; access goes undetected for roughly one month.
  • KDDI detects the intrusion, blocks the attacker, identifies the suspected point of unauthorized access, and implements technical defensive measures, effectively evicting the attacker the same day.
  • KDDI internally confirms that email addresses and passwords used for the affected mail service may have been leaked externally.
  • KDDI Web Communications publishes its own incident notice confirming unauthorized access to its mail service and the CPI rental-server platform.
  • KDDI publicly discloses the breach, notifying that up to 14.22 million current, former, and inactive customer accounts across six ISPs (STNet, JCOM, Chubu Telecommunications, NIFTY, BIGLOBE, KDDI Web Communications) may be affected; regulators are notified.
  • The Japan Times and other outlets report on the disclosed breach and its scale, citing up to 14 million potentially affected accounts.
  • Japanese IT trade press (@IT/atmarkit) reports on the unauthorized access to KDDI's ISP email system, citing the 14.22 million worst-case figure.
  • Continued English-language media coverage characterizes the incident as a shared-infrastructure flaw impacting six ISPs.
  • Follow-on reporting (SecurityWeek, Security Boulevard, BleepingComputer) confirms the root cause as a zero-day exploit in third-party software unrecognized by the vendor at exploitation time, with a vendor patch still in development, and notes that some exposed passwords were stored in plaintext rather than hashed/encrypted.
  • KDDI confirms definitive impact numbers: 12,233,087 email addresses leaked, of which 7,616,173 also had passwords confirmed leaked, refining the initial worst-case estimate of 14.22 million.

Sources cited for KDDI Zero-Day Exploit in Third-Party Software Exposes Up to

Threats related to KDDI Zero-Day Exploit in Third-Party Software Exposes Up to

Detection coverage for TL-2026-1235

As of 2026-07-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1235 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats