History
07/23/20260 new articles
The update sharpens the scale and attribution of both breaches: Aflac’s affected population is still 4.38 million, but KDDI’s incident is now framed as a confirmed third-party software zero-day attack on shared ISP email infrastructure. It also adds that the systems remain under investigation, with downstream misuse still unresolved.
07/22/20260 new articles
The story now includes more specific breach mechanics and quantified exposure, especially KDDI’s zero-day exploitation and confirmed password counts, alongside more detailed Aflac data loss. It also adds explicit regulatory notifications and external cybersecurity involvement, making the incidents feel more fully documented and operationally contained.
- KDDI said a zero-day in third-party software was exploited.
- KDDI confirmed 12.2 million email addresses and 7.6 million passwords were exposed.
- Aflac Japan estimated 4.38 million customers and agents may be affected.
- Aflac reported some bank-account information was exfiltrated.
- External cybersecurity support and regulator notices are now explicit.
07/21/202618 new articles
The story has broadened from a single KDDI breach to a larger Japan-focused breach wave, with Aflac Japan now a co-equal incident and regulators explicitly in the frame. The main change is a stronger emphasis on parallel, large-scale customer data exposure and response across multiple organizations.
- Aflac Japan disclosed a separate policyholder-portal breach.
- Japanese regulators are now explicitly involved in the disclosures.
- Both incidents are framed as exposing personal data and login credentials.
- Operational response now includes suspending affected services.
- The reporting highlights unresolved uncertainty about misuse and exposure details.
06/29/20260 new articles
No material change is evident between the two versions. The breach description, scope, response steps, and affected entities are unchanged.
06/29/20260 new articles
No material change is evident between the two versions. The breach details, affected scale, response steps, and regulatory notification remain the same.
06/29/20263 new articles
The main update is that KDDI now explicitly told affected users to reset passwords and turn on two-factor authentication, making the remediation guidance more direct and urgent. The story also expands slightly with named affected ISPs and confirmation of contact with those providers.
06/29/2026Topic Formed
KDDI disclosed a breach in a shared email system used by multiple Japanese internet service providers, with up to 14.2 million email accounts and passwords potentially exposed. The company said attackers exploited a vulnerability in third-party software, then blocked the intrusion, notified regulators, and began working with affected ISPs. The incident matters because it spans several providers and could enable account compromise if exposed credentials were usable.