< Back to all clusters
[BUSINESS] · Japan · 6 sources

started · updated

KDDI receives administrative guidance following massive email system data breach

Japan's Personal Information Protection Commission has issued administrative guidance to KDDI Corporation following a major data breach involving its email system for internet service providers. The breach, which occurred on June 17, exploited a software vulnerability to gain unauthorized access to the system.

The incident resulted in the leak of IDs and passwords for approximately 12.23 million users. Notably, the passwords for over 7.6 million users were stored in plain text, potentially allowing unauthorized third parties to access email boxes.

The Commission found that KDDI failed to implement sufficient technical safety management measures, such as adequate access controls, to prevent lateral movement by attackers and minimize damage. KDDI has been instructed to improve its security measures and report on its progress and recurrence prevention plans by October 19. The Commission also issued guidance to certain service providers involved in the storage of plain-text passwords.

Entities

KDDI Corporation · Personal Information Protection Commission