Executive Summary
In June 2026, Japanese telecommunications giant KDDI detected unauthorized access to its email platform, affecting multiple internet service providers (ISPs) including STNet, JCOM, Chubu Telecommunications, NIFTY Corporation, and BIGLOBE. The breach, initiated on May 16, exploited a zero-day vulnerability in third-party software, leading to the exposure of approximately 12.23 million email addresses and 7.61 million passwords. KDDI promptly blocked the attackers upon discovery on June 17 and implemented defensive measures to secure the compromised systems.
This incident underscores the critical importance of securing third-party software components, as vulnerabilities in such software can serve as entry points for attackers. Organizations are urged to conduct thorough security assessments of third-party tools and implement robust monitoring systems to detect and respond to unauthorized access promptly.
Why This Matters Now
The KDDI breach highlights the escalating risks associated with zero-day vulnerabilities in third-party software, emphasizing the need for organizations to enhance their security posture and vigilance against such emerging threats.
Attack Path Analysis
Attackers exploited a zero-day vulnerability in third-party software to gain unauthorized access to KDDI's email platform. They escalated privileges within the compromised system to access sensitive data. The attackers moved laterally across interconnected systems to expand their access. They established command and control channels to maintain persistent access. Sensitive data, including email addresses and passwords, was exfiltrated from the compromised systems. The breach impacted over 12 million individuals, leading to potential unauthorized access to their email accounts.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited a zero-day vulnerability in third-party software to gain unauthorized access to KDDI's email platform.
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Obtain Capabilities: Exploits
Exploitation for Defense Evasion
Account Discovery: Email Accounts
OS Credential Dumping
Data from Cloud Storage
Exfiltration Over Web Service: Exfiltration to Cloud Storage
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Asset Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
Direct sector impact as KDDI telecom breach exposed 12+ million email credentials, demonstrating vulnerability to zero-day exploits in email platforms and infrastructure systems.
Internet
Multiple ISP operators affected including JCOM and NIFTY, with email platform compromise highlighting risks from third-party software vulnerabilities and credential exposure.
Information Technology/IT
Zero-day vulnerability in third-party software enabled breach, emphasizing need for enhanced endpoint detection, traffic encryption, and egress security controls.
Financial Services
Exposed credentials create account takeover risks requiring zero trust segmentation, anomaly detection, and compliance with data protection regulations like NIST frameworks.
Sources
- Telco giant KDDI says data breach affects over 12 million peoplehttps://www.bleepingcomputer.com/news/security/japanese-telecom-giant-kddi-says-data-breach-affects-12-million-people/Verified
- 12 million email addresses and 7 million passwords breached in KDDI cyberattackhttps://www.japantimes.co.jp/business/2026/07/07/companies/kddi-passwords-number/Verified
- KDDIのメール不正アクセス、パスワード漏洩は761万件https://www.watch.impress.co.jp/docs/news/2122775.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have significantly limited the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While initial access may still occur, the attacker's ability to exploit the compromised system could be significantly constrained, reducing the potential for further malicious activities.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges could be significantly constrained, reducing the risk of unauthorized access to sensitive data.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally across interconnected systems could be significantly constrained, reducing the risk of widespread access.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish and maintain command and control channels could be significantly constrained, reducing the risk of persistent unauthorized access.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data could be significantly constrained, reducing the risk of data breaches.
The overall impact of the breach could be significantly constrained, reducing the number of affected individuals and the severity of unauthorized access.
Impact at a Glance
Affected Business Functions
- Email Services
- Customer Account Management
Estimated downtime: N/A
Estimated loss: N/A
Email addresses of approximately 12.23 million users and passwords of about 7.61 million users were exposed.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to limit lateral movement and contain potential breaches.
- • Deploy East-West Traffic Security controls to monitor and restrict internal traffic flows.
- • Utilize Multicloud Visibility & Control to detect and respond to anomalous activities across cloud environments.
- • Enforce Egress Security & Policy Enforcement to prevent unauthorized data exfiltration.
- • Adopt Threat Detection & Anomaly Response mechanisms to identify and mitigate threats in real-time.



