Visualização normal
-
ASEC BLOG
-
June 2026 Dark Web Threat Actor Trend Report
Note The June 2026 Dark Web Threat Actor Trend Report focuses on trends among threat actors—including hacktivists—operating on the deep web and dark web. It is noted that the accuracy of some information could not be verified. Major Issues In Malaysia, a series of website defacement and compromise incidents targeting local development agencies and public […]
-
Firewall Daily – The Cyber Express

-
Japan’s Aflac, KDDI, Sapporo, Nidec: Four Breaches, One Common Entry Point
Four major Japan cyberattacks reported within two weeks point to a common trend, with attackers gaining access through subsidiaries and third-party infrastructure rather than corporate headquarters. While the incidents affected companies from different industries, including insurance, telecommunications, brewing, and manufacturing, the breaches shared one notable characteristic. Rather than directly compromising corporate headquarters, attackers gained access through subsidiaries, overseas oper
Japan’s Aflac, KDDI, Sapporo, Nidec: Four Breaches, One Common Entry Point
![]()
Four major Japan cyberattacks reported within two weeks point to a common trend, with attackers gaining access through subsidiaries and third-party infrastructure rather than corporate headquarters. While the incidents affected companies from different industries, including insurance, telecommunications, brewing, and manufacturing, the breaches shared one notable characteristic.
Rather than directly compromising corporate headquarters, attackers gained access through subsidiaries, overseas operations, or third-party infrastructure.
The affected organizations include Aflac Japan, KDDI, Sapporo Holdings, and Nidec, each of which reported separate cyber incidents during the second half of June 2026. Although the attacks involved different circumstances, the disclosures point to an expanding attack surface that extends well beyond an organization's primary network.
Aflac Japan Breach Exposed Customer Data
Aflac Japan disclosed on June 30 that attackers accessed its Japanese operations between June 15 and June 25. According to the company, approximately 4.38 million customers and agents were affected, with a subset of records including bank account information used for insurance premium payments.
The insurer stated that the incident was limited to its Japanese business and did not affect its U.S. operations.
While the company has not attributed the attack to any specific threat group, the reported tactics resemble social engineering techniques previously associated with Scattered Spider.
KDDI Incident Impacts Millions Through Shared Platform
Telecommunications provider KDDI reported unauthorized access involving an email platform used by multiple Japanese internet service providers.
The company said the incident stemmed from a vulnerability in third-party software, potentially exposing up to 14.22 million email account records across six ISPs.
The breach demonstrates how a single vulnerability within shared infrastructure can affect multiple organizations simultaneously.
Sapporo Holdings and Nidec Target Overseas Subsidiaries
Sapporo Holdings disclosed suspected unauthorized access involving two overseas subsidiaries, Singapore-based Pokka and Canadian brewer Sleeman. The company detected suspicious activity, shut down affected systems, and launched an investigation to determine whether any information had been accessed or stolen.
Meanwhile, manufacturing company Nidec confirmed a ransomware attack targeting its Taiwanese subsidiary, Nidec Chaun Choung Technology.
The BlackField ransomware group claimed responsibility for the attack, alleging it had stolen more than two terabytes of company data, including employee, financial, procurement, manufacturing, legal, and IT records. The group reportedly demanded a $2 million ransom.
A Shared Pattern Across the Japan Cyberattacks
Despite involving different industries and attack methods, the four Japan cyberattacks reveal a similar point of compromise.
Aflac's breach was limited to its Japanese business. KDDI's exposure originated from a shared email platform relying on vulnerable third-party software. Sapporo's investigation centers on overseas subsidiaries, while Nidec's ransomware incident affected its Taiwan-based operation rather than its headquarters.
These cases suggest attackers are increasingly targeting subsidiaries, shared services, overseas business units, and technology partners instead of attempting to breach an organization's primary corporate network.
Growing Risks Across the Extended Enterprise
The incidents highlight the importance of treating subsidiaries and external partners as part of the organization's overall security perimeter.
Organizations that rely on overseas offices, acquired businesses, vendors, or shared platforms may inherit additional cybersecurity risks if those environments are not protected to the same standard as corporate headquarters.
The KDDI incident illustrates how third-party dependencies can significantly increase the scale of a breach, while the Nidec cyberattack demonstrates how ransomware groups continue to combine data theft with extortion demands.
The reported tactics observed in the Aflac incident also reinforce the continued effectiveness of social engineering as an initial access method.
While investigations into several of the incidents remain ongoing, the recent disclosures underscore a broader trend. As enterprise environments become increasingly interconnected, subsidiaries, shared infrastructure, and external technology providers are becoming attractive targets for attackers seeking indirect access to larger organizations.
-
Security | TechRepublic
-
Japanese Telecom Giant Says Breach May Expose 14.2 Million Email Accounts
KDDI says a breach may have exposed email addresses and passwords for up to 14.2 million ISP accounts across six providers. The post Japanese Telecom Giant Says Breach May Expose 14.2 Million Email Accounts appeared first on TechRepublic.
Japanese Telecom Giant Says Breach May Expose 14.2 Million Email Accounts
KDDI says a breach may have exposed email addresses and passwords for up to 14.2 million ISP accounts across six providers.
The post Japanese Telecom Giant Says Breach May Expose 14.2 Million Email Accounts appeared first on TechRepublic.
-
Security Affairs
-
KDDI Data Breach Impacts up to 14.2 Million Email Accounts at Six ISPs
KDDI Corporation disclosed a breach affecting up to 14.2 million email accounts after attackers exploited a vulnerability in third-party software. KDDI Corporation disclosed a data breach that exposed up to 14.2 million email accounts across six Japanese internet service providers. KDDI Corporation is one of Japan’s largest telecommunications companies. It employs more than 60,000 people and generates annual revenue of roughly ¥5.9 trillion (about US$40 billion). The company provides mob
KDDI Data Breach Impacts up to 14.2 Million Email Accounts at Six ISPs
KDDI Corporation disclosed a breach affecting up to 14.2 million email accounts after attackers exploited a vulnerability in third-party software.
KDDI Corporation disclosed a data breach that exposed up to 14.2 million email accounts across six Japanese internet service providers.
KDDI Corporation is one of Japan’s largest telecommunications companies. It employs more than 60,000 people and generates annual revenue of roughly ¥5.9 trillion (about US$40 billion). The company provides mobile, fixed-line, broadband, cloud, data center, IoT, and digital services, operating primarily in Japan while serving enterprise customers across Asia and other international markets.
The company detected the intrusion on June 17, quickly blocked the attackers, and launched an investigation. According to KDDI, the breach was caused by a vulnerability in third-party software used by its email system. The company is continuing its investigation while assessing the full impact of the incident.
“On June 17, 2026, we confirmed that some information from email services provided by various ISP operators (hereinafter referred to as “the email service”) may have been leaked to an external party in the email system (hereinafter referred to as “the System”) that we provide to Internet Service Providers (hereinafter referred to as “ISP operators”).” reads the data breach notice.
“On the same day, we modified the System to prevent further damage. We have identified the suspected location of the Unauthorized Access and implemented technical defense measures.”
KDDI said it has reported the breach to Japan’s privacy and telecommunications regulators and is taking the required legal and regulatory steps. The incident affected the email services of six internet providers: STNet, KDDI Web Communications, JCOM, Chubu Telecommunications, Nifty, and BIGLOBE.
The company confirmed said that email addresses and passwords may have been exposed, including accounts belonging to former and inactive customers. While passwords were stored in hashed or encrypted form, the company warned they may have been obtained by attackers. KDDI is coordinating response efforts, and is urging all impacted users to change their email passwords immediately to reduce the risk of unauthorized access.
“We are also proceeding with discussions and implementation of countermeasures. While we have implemented technical security measures for this system, there is a possibility that your email address and password may have been illegally obtained by a third party due to this unauthorized access.” concludes the notice. “To ensure the protection of your data and eliminate future and potential risks, you will need to change your email password. We ask that you check the information provided by your ISP provider and take immediate action. We will continue to work with ISP providers to inform customers and take appropriate action to encourage prompt password changes.”
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, data breach)
-
Firewall Daily – The Cyber Express

-
KDDI Data Breach May Have Exposed Up to 14.22 Million Email Accounts
Japanese telecommunications company KDDI has disclosed a major cybersecurity incident in which up to 14.22 million email addresses and passwords may have been exposed through systems used by multiple internet service providers. The KDDI data breach has now become one of the most recent security events involving shared ISP infrastructure in Japan. The company confirmed that the data breach at KDDI was detected on June 17, 2026, after unauthorized access was identified in an email system provi
KDDI Data Breach May Have Exposed Up to 14.22 Million Email Accounts
![]()
KDDI Data Breach Linked to Third-Party Software Vulnerability
The data breach at KDDI impacted email services operated through six internet service providers: STNet, KDDI Web Communications, JCOM, Chubu Telecommunications, Nifty, and Biglobe. Affected services include Pikara Hikari Service, Pikara Mobile Service, Oshigoto Pikara Service, CPI rental server email services, J:COM NET, Commufa Hikari, Business Commufa, @nifty Mail, and BIGLOBE Mail. KDDI’s investigation found that the threat actor exploited vulnerabilities in third-party software integrated into the email system. This allowed unauthorized access to information associated with user mailboxes, potentially exposing credentials needed to operate email accounts. According to the company, the compromised data may include email addresses and passwords linked to user accounts created across the affected services. The maximum number of records potentially exposed is estimated at 14.22 million. This figure includes inactive accounts and users who had previously closed their services. Some passwords were stored in hashed or encrypted form, though KDDI emphasized that the number represents a worst-case estimate while investigations continue. In its official disclosure, KDDI apologized to ISP partners, customers, and stakeholders for the disruption caused by the incident. The company also confirmed that it is cooperating with Japan’s Personal Information Protection Commission and the Ministry of Internal Affairs and Communications in line with legal and regulatory obligations related to the KDDI data breach.KDDI Data Breach Prompts Password Reset Measures and Ongoing Response
Following the detection of the data breach at KDDI, the company has been working with affected ISPs to notify users and encourage them to change their passwords immediately. KDDI stated that although security controls have been strengthened, there remains a possibility that email credentials were obtained by a threat actor, making user action necessary to reduce ongoing risk. The company has been contacting affected providers since June 17 and continues to coordinate mitigation efforts, including customer alerts and system-level countermeasures. It has also urged users to follow guidance issued by their respective ISPs and update login credentials without delay.Rising Cybersecurity Risks Highlighted by KDDI Data Breach
The KDDI data breach has emerged amid a broader increase in cyberattacks affecting Japanese organizations. According to Tokyo Shoko Research, listed companies and their subsidiaries reported 180 personal information breach cases in 2025, exposing data tied to approximately 30.6 million individuals. More than 60% of these incidents involved unauthorized access or malware infections. Ransomware activity has also continued to rise, with Japanese police confirming 226 cases of ransomware-related incidents last year, marking the second-highest total on record. While small and midsize firms accounted for roughly 60% of victims, several large organizations also suffered significant operational disruption. Among them, Asahi Group Holdings reported that a ransomware attack in September exposed 115,513 personal records and disrupted production and distribution across most domestic facilities, forcing manual order processing for an extended period. Similarly, Askul disclosed that a ransomware incident discovered in October resulted in the exposure of approximately 740,000 records involving customers, corporate clients, and employees.-
ASEC BLOG
-
May 2026 Dark Web Breach Incident Trend Report
Notes the May 2026 Dark Web Breach Incident Trend Report is organized around the major cases of Data Breaches posted on the deep web and dark web forums. due to the nature of the source, some of the information may not be fully verifiable as to whether it is true or not, and is therefore […]