What happened in the KDDI data breach?
Attackers exploited a vulnerability in unnamed third-party software to reach a shared email platform serving six Japanese ISPs — KDDI, STNet, JCOM, Chubu Telecommunications, NIFTY, and BIGLOBE. KDDI disclosed that the email addresses and passwords of up to 14.2 million current, former, and inactive customers may have been exposed.
Answered in
One Vendor Flaw Just Exposed 14.2 Million Logins Across Six Japanese ISPsA flaw in one unnamed vendor's software let attackers into a shared email platform, exposing up to 14.2 million accounts across six Japanese ISPs.
Read the full analysisOther questions this article answers
More development best practices questions
- How many outage reports did Claude and ChatGPT get on July 14, 2026?
- What did Anthropic's own status page say about the July 14 Claude outage?
- Did Claude have more outages after July 14?
- What did ChatGPT's status checker say was wrong?
- Is this outage pattern actually unusual for AI providers?
- What GitHub Actions vulnerability did the attacker exploit?
- How many npm packages were compromised, and how widely were they used?
- What did the malicious payload actually do?
Every answer on Crashtech is written by the editor of the article it comes from — never auto-summarised. Browse all answers or the Development Best Practices beat.