The images in this article were generated with artificial intelligence. How we publish
The Japanese operator KDDI has confirmed an intrusion into one of its email systems that provides services to five national ISPs, an incident that again shows the fragility of software supply chains and the risk to millions of users. According to the company's official note, the intrusion was detected on June 17 and the attacker's access was blocked, but preliminary investigation suggests that 14.22 million addresses and passwords of accounts - including old and inactive - could have been exposed(see KDDI communication) Here.).
Those affected are not just KDDI direct customers: the leak impacts the mail services of STNet, JCOM, Chubu Telecommunications, NIFTY and BIGLOBE, which multiplies the scope and potential consequences. Specialized press reports point to the magnitude and technical context of the incident, and stress that the input vector was a vulnerability in a third-party software that KDDI integrated into its platform ( BleepingComputer report).

That the origin was an external piece reinforces a recurring lesson: safety no longer depends only on its own perimeters. Organizations should assume that third-party components may contain critical failures and design compensatory controls, from segmentation and hardening to penetration tests and attack simulations that detect leaks before attackers.
KDDI states that some of the passwords were stored in "hasheed and / or encrypted" form, a key difference that reduces the risk of immediate abuse. However, the company did not specify which algorithms were used or which proportion of passwords was legible in clear text. Without transparency about cryptographic methods and the percentage of data in flat text, it is difficult to quantify the real danger and that must be a demand point for users and regulators.
For potentially affected users, urgent measures are clear: change the password of the affected mail and any other service where that credential is reused, activate strong authentication mechanisms (2FA or, preferably, physical keys) and monitor attempts at phishing or unauthorized access. In addition, using a password manager to generate unique and complex keys significantly reduces the risk of supplanting by credential stuffing.
Providers and operators must take immediate technical action: force the restoration of committed credentials, invalidate tokens and active sessions, analyse logs to detect side movements and persistencies, and accelerate the audit of the third party software involved. In the medium term, it is essential to strengthen the third-party management programme, to require safety SLA and patch evidence, and to carry out continuous defence and detection tests.

The incident also has regulatory and reputational implications. KDDI notified the Commission for the Protection of Personal Information and the Ministry of Internal Affairs and Communications of Japan; such communications may give way to additional mitigation sanctions or requirements under local legislation. Rapid and transparent communication is key to minimizing legal damage and restoring confidence but they must be accompanied by technical evidence and concrete measures.
Finally, this case is a reminder for security professionals: it is not enough to park after public notice. It is necessary to invest in proactive detection, such as attack simulations and rule coverage tests in ICES / EDR, and in organizational processes that ensure coordinated response with partners and suppliers. The complexity of the current digital ecosystem requires controls that address both technical and governance risks.
If you want to deepen on third-party risk management and good response practices, the NIST guide on supplier management and the official documentation of the Japan Data Protection Agency can serve as a supplementary reference.
Related
More news on the same subject.

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...

Isolated-vm Vulnerability allows memory corruption and sandbox escape
Security researchers have revealed critical vulnerability in the open source isolated-vm library - a Node.js binding to run unreliable JavaScript in isolated V8 engine instances...

Microsoft links more than 30 domains to MacSync Stealer for macOS with active data exfiltration
Microsoft has linked more than thirty web domains to MacSync Stealer, a malicious program focused on macOS that steals information. Microsoft researchers describe a repeated cha...

The massive purchase of expired domains drives fraud, malware and streaming pirate: the business behind the dropcatch
An intelligence report on DNS published by Infoblox and disseminated by specialized media confirms that criminals are buying large-scale expired domains - the so-called dropcatc...

AmnesiaStealer MacOS malware that steals credentials and controls real-time browser sessions
Security researchers have documented a new malware family aimed at macOS - called AmnesiaStealer - that combines a dropper in shell, an infostealer written in Rust and a remote ...

Lazarus Group returns with a campaign aimed at defense and aerospace that combines kernel rootkit and social recruitment
The North Korean group known as Lazarus Group has again shown that it continues to improve intrusion techniques for the defence and aerospace industry. According to the research...