KDDI exposes 14.22 million accounts for third-party vulnerability: the new security reality in the supply chain

Author: Published 3 min de lectura 171 reading

The images in this article were generated with artificial intelligence. How we publish

The Japanese operator KDDI has confirmed an intrusion into one of its email systems that provides services to five national ISPs, an incident that again shows the fragility of software supply chains and the risk to millions of users. According to the company's official note, the intrusion was detected on June 17 and the attacker's access was blocked, but preliminary investigation suggests that 14.22 million addresses and passwords of accounts - including old and inactive - could have been exposed(see KDDI communication) Here.).

Those affected are not just KDDI direct customers: the leak impacts the mail services of STNet, JCOM, Chubu Telecommunications, NIFTY and BIGLOBE, which multiplies the scope and potential consequences. Specialized press reports point to the magnitude and technical context of the incident, and stress that the input vector was a vulnerability in a third-party software that KDDI integrated into its platform ( BleepingComputer report).

KDDI exposes 14.22 million accounts for third-party vulnerability: the new security reality in the supply chain
Image generated with IA.

That the origin was an external piece reinforces a recurring lesson: safety no longer depends only on its own perimeters. Organizations should assume that third-party components may contain critical failures and design compensatory controls, from segmentation and hardening to penetration tests and attack simulations that detect leaks before attackers.

KDDI states that some of the passwords were stored in "hasheed and / or encrypted" form, a key difference that reduces the risk of immediate abuse. However, the company did not specify which algorithms were used or which proportion of passwords was legible in clear text. Without transparency about cryptographic methods and the percentage of data in flat text, it is difficult to quantify the real danger and that must be a demand point for users and regulators.

For potentially affected users, urgent measures are clear: change the password of the affected mail and any other service where that credential is reused, activate strong authentication mechanisms (2FA or, preferably, physical keys) and monitor attempts at phishing or unauthorized access. In addition, using a password manager to generate unique and complex keys significantly reduces the risk of supplanting by credential stuffing.

Providers and operators must take immediate technical action: force the restoration of committed credentials, invalidate tokens and active sessions, analyse logs to detect side movements and persistencies, and accelerate the audit of the third party software involved. In the medium term, it is essential to strengthen the third-party management programme, to require safety SLA and patch evidence, and to carry out continuous defence and detection tests.

KDDI exposes 14.22 million accounts for third-party vulnerability: the new security reality in the supply chain
Image generated with IA.

The incident also has regulatory and reputational implications. KDDI notified the Commission for the Protection of Personal Information and the Ministry of Internal Affairs and Communications of Japan; such communications may give way to additional mitigation sanctions or requirements under local legislation. Rapid and transparent communication is key to minimizing legal damage and restoring confidence but they must be accompanied by technical evidence and concrete measures.

Finally, this case is a reminder for security professionals: it is not enough to park after public notice. It is necessary to invest in proactive detection, such as attack simulations and rule coverage tests in ICES / EDR, and in organizational processes that ensure coordinated response with partners and suppliers. The complexity of the current digital ecosystem requires controls that address both technical and governance risks.

If you want to deepen on third-party risk management and good response practices, the NIST guide on supplier management and the official documentation of the Japan Data Protection Agency can serve as a supplementary reference.

Coverage

Related

More news on the same subject.