Protect.Computer
NEWS

KDDI Cyberattack Exposed 12 Million Email Accounts in Japan

· 1 min read · Data hijack Identity theft
KDDI Cyberattack Exposed 12 Million Email Accounts in Japan

One of Japan’s largest telecommunications companies, KDDI, has confirmed that a cyberattack on an email platform it operates exposed more than 12.2 million customer email addresses and 7.6 million passwords. Attackers exploited a vulnerability in third-party software used by the platform, which KDDI operates for five Japanese internet service providers. KDDI says it patched the flaw and restricted access after detecting the intrusion, and its investigation found no evidence the attackers moved beyond the compromised email system.

If you’re a customer of KDDI’s email services or one of the affected ISPs, your email address and possibly your login password may now be in criminal hands. Act quickly: change your email account password, and if you’ve reused that same password on any other sites or apps — banking, social media, streaming — change those too. Be extra cautious about any email arriving in your inbox that claims to be from KDDI, your ISP, or a security team asking you to verify your account.

How to check if you’re affected

Affected products include email accounts managed through KDDI’s email platform and the five Japanese ISPs whose webmail service it powered. If you receive email services from a Japanese ISP and haven’t received a breach notification yet, log in and change your password now, then enable two-step verification if your provider offers it. Use a unique password you haven’t used anywhere else.

Sources

Related reading