More on the topic...
Generating detailed summary...
Failed to generate summary. Please try again.
KDDI, one of Japan’s biggest telecoms, left roughly 142 million records of its managed email service exposed online for at least two months. A security researcher discovered an open Amazon S3 bucket containing user names, email addresses, hashed passwords and some internal logs. Although the passwords were salted and hashed, the algorithm used (SHA-1) is considered weak today, meaning skilled attackers could crack many of them.
KDDI says the leak involved its “KDDI Business Mail” system used by small and midsize firms. The company spotted unusual access in mid-April and locked down the bucket by late May. It notified customers in early June and urged them to change passwords. No evidence so far points to active misuse, but third-party analysts warn stolen credentials often surface for spam, phishing or brute-force attacks weeks or months later.
This lapse follows several high-profile data spills in Japan. Critics note KDDI’s configuration error should have been caught in routine audits. The telco says it’s beefing up its cloud-storage checks and rolling out stronger hashing on all its email platforms by year’s end.
Questions about this article
No questions yet.