Latest / Tech Talks With Kinsoft / KDDI – One Flaw, Six ISPs, 14 Million Exposed Mailboxes
Transcript
- 0:00So imagine this. You wake up on a random morning
- 0:04in June 2020 slugs. You check your phone and
- 0:07you find out your email provider has been completely
- 0:09compromised. Which is pretty much the worst way
- 0:12to start your day. Right. It's awful. Your stomach
- 0:14just drops and you know you immediately start
- 0:17doing the mental math of like every single thing
- 0:20connected to that email address your bank your
- 0:22shopping accounts everything. Oh yeah. The panic
- 0:24sets in instantly. Exactly. But. Here's the real
- 0:28shocker of this specific incident. For a huge
- 0:31portion of these victims, the security vulnerability
- 0:33that exposed their entire digital lives didn't
- 0:36even come from the provider they actually signed
- 0:38up with. Yeah, that's the wild part. It came
- 0:40from a completely different brand, like one they
- 0:42might never have even heard of, just sharing
- 0:44the same invisible basement. It's a profoundly
- 0:47unsettling scenario, honestly. And it really
- 0:50forces us to confront this reality of where our
- 0:53data actually lives. We just assume that when
- 0:57we buy a service from company A, our data stays
- 0:59safe within the walled garden of company A. Right,
- 1:02like it's locked in a vault with their logo on
- 1:04it. Exactly. But we don't realize that company
- 1:06A and company B and company C, they're often
- 1:10just different marketing storefronts. They're
- 1:13built on top of the exact same vulnerable foundation.
- 1:16Which brings us to what we're talking about today.
- 1:18Welcome to today's Deep Dive, where we are really
- 1:21going to unpack the architecture of that shared
- 1:23foundation. We're looking at a massive cyber
- 1:26incident involving the Japanese telecom giant
- 1:29KDDI. An absolute behemoth of a company. Yeah,
- 1:31tens of billions in revenue. And we're drawing
- 1:34from this really fascinating incident analysis
- 1:36by Tech Talks with Kinsoft. So our mission today
- 1:40is to kind of decode how a flaw in an unnamed
- 1:42third -party software system managed to expose
- 1:45up to 14 .2 million accounts. And we really need
- 1:49to look closely at the mechanics behind that
- 1:51exposure because... I mean, a number like 14
- 1:53million, that doesn't just happen by accident.
- 1:55No, definitely not. It is the result of compounding
- 1:57systemic vulnerabilities. And just to set the
- 2:00stakes here for everyone listening, this isn't
- 2:02just some story about a random tech glitch, right?
- 2:05It's a massive lesson in what we call concentration
- 2:07risk, the hidden dangers of credential reuse,
- 2:10and honestly, why the exact wording of a company's
- 2:14public apology might be the most crucial part
- 2:17of a data breach. Oh, absolutely. The PR spin
- 2:19is always telling. Right. OK, let's untack this.
- 2:22Let's just lay out the timeline and the scale
- 2:23first. So late June 2026, KDDI confirms this
- 2:28massive breach. that they actually detected on
- 2:30June 17th. Yeah, right in the middle of the month,
- 2:32they spot this unauthorized access. Right, and
- 2:35the attackers guard in by exploiting a vulnerability
- 2:37in some third -party software that ran a shared
- 2:39email system. And the ultimate fallout here is
- 2:42that email addresses and passwords for up to
- 2:4414 .2 million users were exposed. Which is just
- 2:48a staggering volume of data. It really is, and
- 2:51that includes, you know, active users, former
- 2:52users, and accounts that had just been sitting
- 2:55dormant for years to kind of wrap our heads.
- 2:58around this it's like well think of living in
- 3:00a massive ultra secure high -rise building okay
- 3:03I like this analogy right you think you're safe
- 3:06but then you discover the contractor used the
- 3:09exact same master key for all six high -rises
- 3:12on the entire block that is a brilliant way to
- 3:15visualize it because that's exactly how enterprise
- 3:17software architecture works today But, you know,
- 3:20what's fascinating here is that from a pure incident
- 3:23response perspective, KDDI actually did a few
- 3:27things right. Wait, really? Yeah, I know it sounds
- 3:30crazy given the numbers. Because exposing 14
- 3:32million accounts sounds like a colossal failure
- 3:34on literally every front. It does sound like
- 3:37it. Yeah. But the Kinsoft analysis points out
- 3:39that when they detected the compromise on the
- 3:4117th, they actually acted decisively. They successfully
- 3:45blocked the attacker. They stopped the ongoing
- 3:48exfiltration of data. Oh, wow. OK, so they didn't
- 3:51just let it bleed out. Exactly. And they didn't
- 3:54try to sweep it under the rug internally either.
- 3:57They immediately began notifying Japan's privacy
- 4:00regulators and they reached out to the other
- 4:02Internet service providers who were affected.
- 4:04I mean, their containment protocols actually
- 4:06worked. Right. But containment doesn't undo the
- 4:09fact that 14 million records are already gone.
- 4:12Precisely. The core problem that makes this so
- 4:15terrifying isn't their response time. The alarm
- 4:17bells are ringing because of the sheer scale
- 4:19of the initial exposure, the blast radius. Right,
- 4:22the blast radius, which leads perfectly into
- 4:24the first major structural issue from the Kinsloff
- 4:27report, this idea of concentration risk. Because
- 4:30that massive number, it isn't just because KDI
- 4:33has a lot of customers. Not at all. It is entirely
- 4:35due to that shared master key architecture you
- 4:38mentioned earlier. In cybersecurity, we talk
- 4:40constantly about blast radius, like how far does
- 4:43the damage spread when one single component fails?
- 4:46And in this case, it spread really far. Unbelievably
- 4:48far. Because that shared email platform wasn't
- 4:51just for KDI's direct customers. It was the silent
- 4:54engine sitting behind six completely different
- 4:56ISP brands. Six different brands. So it's KDDI
- 4:59plus... Let me check the list here. JCOM, Nifty,
- 5:03Big Lobe, Chubu Telecommunications, and STNet.
- 5:06Yeah. And to the average consumer, those are
- 5:09competitors. Yeah, totally separate companies.
- 5:11Exactly. So imagine you had a terrible customer
- 5:14service experience with KDDI five years ago.
- 5:17You get mad, you cancel, and you intentionally
- 5:19switch to NiftyY, thinking you're moving your
- 5:23data to a safer, separate infrastructure. Right.
- 5:25You're like, take that, KDDI. You're right. But
- 5:28underneath the distinct branding and the different
- 5:30websites, you are literally just moved to a different
- 5:33server rack in the exact same backend environment.
- 5:35Man, that is frustrating. So what does this all
- 5:39mean for you listening to this deep dive right
- 5:41now? Think about your own workplace. Think about
- 5:44the digital tools you rely on every day. We all,
- 5:47you know, we love the efficiency of shared infrastructure.
- 5:49We rely on it completely. Yeah. It's why we use
- 5:51centralized cloud providers and universal single
- 5:54sign on. But how many of your own business operations
- 5:56quietly depend on a single shared component?
- 6:00Like what happens the day that one piece of third
- 6:02party software just fails? Well, as we see here,
- 6:05the blast radius multiplies exponentially. And
- 6:08this is entirely driven by the business economics
- 6:10of tech consolidation. I mean, from a CFO's perspective,
- 6:14it makes perfect financial sense to centralize
- 6:17your back -end systems across all your subsidiary
- 6:20brands. Oh, sure. You cut costs. Exactly. You
- 6:23reduce your server overhead. You only pay one
- 6:25IT maintenance team instead of six. You streamline
- 6:28your updates. I mean, you are building this incredibly
- 6:30efficient machine. But efficiency always comes
- 6:32with a hidden tax. Always. And the hidden tax
- 6:35of efficiency is extreme fragility. By centralizing
- 6:40everything to save a few bucks, you have effectively
- 6:43subsidized the attacker's return on investment.
- 6:45Subsidized the attacker? Think about it. Instead
- 6:48of a hacker having to figure out six different
- 6:50ways to breach six different companies, they
- 6:52only have to find one single flaw in that shared
- 6:55third -party software. And once they break down
- 6:57that one door? They get the data for all six
- 6:59brands simultaneously. We are building these
- 7:01massive, highly optimized digital towers, but
- 7:04we're balancing them on single points of failure.
- 7:06Which is terrifying. But exposing that shared
- 7:10server isn't even the end of the story. Because
- 7:12the attackers, you know, they aren't just sitting
- 7:14around looking at a spreadsheet of 14 million
- 7:17email addresses. They immediately weaponize that
- 7:20data. Which brings us to the fuel for the fire
- 7:22here. credential stuffing. Yeah, because an email
- 7:26address and a password combo, it's not just an
- 7:29isolated piece of information. It is literal
- 7:31currency in the cyber criminal underground. I
- 7:33think a lot of people just assume like, oh, my
- 7:36telecom provider got hacked, whatever. The worst
- 7:38they can do is read my spam folder. Right. Or
- 7:40look at your old phone bills. Exactly. But the
- 7:42real threat has absolutely nothing to do with
- 7:44the telecom provider at all. Not even a little
- 7:47bit. Attackers do not care about your old emails.
- 7:50What they care about is human psychology. They
- 7:53know that we all suffer from extreme password
- 7:56fatigue. Oh, I certainly do. We all do. You're
- 7:59asked to create an account for everything. Your
- 8:01bank, your pharmacy, your streaming services,
- 8:04the place you order pizza from. And as a result,
- 8:07the vast majority of people just reuse the same
- 8:09two or three passwords across their entire digital
- 8:12life. Here's where it gets really interesting.
- 8:14It's like using the exact same key for your front
- 8:18door, your car, your safe, and your office. So
- 8:21a thief... steals your key ring from, say, a
- 8:24hotel valet. The thief doesn't care about your
- 8:27car in the hotel parking lot. No, they don't
- 8:29care about the hotel at all. Right. They take
- 8:30that key and they walk down every street in your
- 8:33hometown just hitting the unlock button over
- 8:35and over again until your front door at home
- 8:37suddenly clicks open. The vulnerability isn't
- 8:40just the email leak. It's the human habit of
- 8:43password reuse. That is the exact mechanism of
- 8:46credential stuffing. But you have to realize
- 8:49it is happening at a scale and speed that is
- 8:52almost impossible to comprehend. When attackers
- 8:54get a data set from a breach like KDDI, they
- 8:57don't type them in by hand. They feed those millions
- 9:00of username and password pairs into sophisticated
- 9:02automated bot networks. OK, wait, I have to jump
- 9:05in here because don't most modern websites have
- 9:07defenses against that? Like if I type my bank
- 9:09password wrong three times, I get locked out
- 9:11or I have to click on, you know, all the pictures
- 9:13of crosswalks in a CAPTCHA. How are the bots
- 9:16getting past that? That is a great question.
- 9:18And it's where the economics of cybercrime get
- 9:21incredibly advanced. The hackers know all about
- 9:24rate limiting, that defense that locks you out
- 9:28after three tries. To bypass it, they use something
- 9:31called rotating residential proxies. Basically,
- 9:34they route their bot traffic through millions
- 9:37of hijacked home internet connections all around
- 9:40the world. So to your bank's security system,
- 9:43it doesn't look like one hacker in a basement
- 9:45trying 10 ,000 passwords. Oh, wow. It looks like
- 9:4810 ,000 normal people. Exactly. It looks like
- 9:5010 ,000 regular customers sitting in their living
- 9:53rooms trying to log in exactly one time. They
- 9:56fire these stolen credentials at corporate VPNs,
- 9:59healthcare databases, Amazon accounts, all simultaneously.
- 10:03So they just completely circumvent the basic
- 10:05security tripwires. Entirely. And if we connect
- 10:08this to the bigger picture. This exact mechanism
- 10:11is why enterprise IT leaders are so aggressively
- 10:13pushing for zero -trust architecture. It is exactly
- 10:17why you, the listener, are constantly dealing
- 10:19with security friction at work. You mean the
- 10:21endless nagging to use an authenticator app?
- 10:24Yes. The nagging has a very specific critical
- 10:27purpose. This credential stuffing pipeline is
- 10:31why enforced multi -factor authentication MFA
- 10:34is simply no longer optional. Right. Because
- 10:37even if they have the password. Even if the attacker
- 10:39has your exact password from the KDDI breach,
- 10:42if they do not have that temporary six digit
- 10:45token generated on your physical phone, that
- 10:48stolen password is mathematically useless to
- 10:51them. That makes so much sense. It's also why
- 10:53relying on human memory for passwords is just
- 10:55a fundamentally failed security model. Strict
- 10:58password managers and never reusing a password.
- 11:01Those aren't just for tech geeks anymore. They're
- 11:03the only way to structurally break the chain.
- 11:05OK, so we see. how the ghost kitchen architecture
- 11:07allowed the breach to happen in the first place
- 11:09right and we see this devastating economic machinery
- 11:12that takes the stolen data and weaponizes it
- 11:15but um there is another layer to the story that
- 11:17i found incredibly revealing when reading the
- 11:19kinsoft analysis and it happens right after the
- 11:22dust settles ah yes when the company actually
- 11:25has to face the public Yes, the crisis communication.
- 11:28Because the way a company words its breach disclosure
- 11:31might actually be the most vital metric we have
- 11:34to judge their internal culture by. Let's look
- 11:37at KDDI's actual public disclosure. When they
- 11:40announced the breach, they included the specific
- 11:42line noting that, quote, some of the compromised
- 11:46passwords were hashed or encrypted. Right. And
- 11:49they crucially omitted two massive pieces of
- 11:51information there. First, they completely refused
- 11:54to state which specific cryptographic algorithm
- 11:56they used. And the second, they refused to clarify
- 11:59what percentage of the passwords fell under the
- 12:01category of some versus how many were just left
- 12:04completely unprotected in plain text. Now, wait,
- 12:06let me play devil's advocate for a second here,
- 12:08because when I read the passwords were encrypted,
- 12:10my immediate reaction is relief. It sounds reassuring.
- 12:13If a password is run through a hashing algorithm,
- 12:15it's scrambled into random gibberish. So even
- 12:18if the hackers stole the whole database, isn't
- 12:20the data essentially useless to them anyway?
- 12:22Well, this raises an important question, and
- 12:24it completely exposes the danger of vague reassurance.
- 12:27Because not all encryption is created equal.
- 12:30In fact, saying your data is hashed without naming
- 12:33the algorithm, it's the cybersecurity equivalent
- 12:36of saying your front door is locked without mentioning
- 12:39that the lock is made of wet cardboard. Wait,
- 12:42really? But a hash is a one -way mathematical
- 12:44function, isn't it? Like you can't just unhash
- 12:47something. In theory, yes. If KDDI used a modern
- 12:52computationally expensive hashing algorithm,
- 12:54something like bcrypt or Argon2, along with a
- 12:57unique randomized salt for every single user,
- 12:59then you're totally correct. It would take forever
- 13:01to crack. Right. It would take an attacker an
- 13:04absurd amount of computing power and literally
- 13:06decades of time to guess those passwords. We
- 13:10don't actually know if they use those modern
- 13:11algorithms. Because they wouldn't say. Because
- 13:13they wouldn't say. And a lot of older legacy
- 13:16IT environments, which, by the way, are the exact
- 13:18kind of environments that get rolled up these
- 13:19massive corporate consolidations companies, are
- 13:21often still using obsolete hashing algorithms
- 13:23like MD5 or SHA1. And those are bad. They were
- 13:27designed decades ago to be fast, which is the
- 13:31exact opposite of what you want for password
- 13:33security. You want password hashing to be slow
- 13:35and expensive. Okay, but even if it's an older
- 13:38algorithm, if it's still a one -way function,
- 13:40how do the hackers actually crack it? Oh, they
- 13:43don't even bother cracking them manually. They
- 13:45use something called a rainbow table. A rainbow
- 13:47table. Yeah, because older algorithms like MD5
- 13:50compute so incredibly fast, hackers have already
- 13:54pre -calculated the hashes for literally... billions
- 13:57of common passwords. Right. Like they already
- 13:59had these massive lookup tables sitting on their
- 14:01hard drives. Yeah. So if they steal a database
- 14:03of MDFI hashes, they don't compute anything.
- 14:06They just compare the gibberish in your database
- 14:08against their pre -calculated rainbow table.
- 14:11It takes a matter of seconds to reverse engineer
- 14:13millions of passwords. Wow. Okay. So if KDDI
- 14:16used an outdated algorithm, the fact that they
- 14:19said the passwords were hashed offers basically
- 14:22zero actual protection against a modern attacker?
- 14:25Correct. And by withholding the name of the algorithm,
- 14:28KDDI is actively preventing security professionals
- 14:31and their own users from accurately calculating
- 14:34their true risk level. It is the difference between
- 14:37genuine transparency and just, you know, PR damage
- 14:41control. Which brings us to that second omission,
- 14:44which honestly feels even more deceptive to me.
- 14:46Using the word some to describe how many passwords
- 14:50were protected. Oh, in statistics and cybersecurity,
- 14:52some is a terrifying word. Right. Because if
- 14:55some means, say, 99 percent of the 14 million
- 14:59accounts were strongly encrypted and maybe 1
- 15:01percent slipped through in plain text because
- 15:02of some weird logging error. I mean, that's a
- 15:05problem, but it's a contained problem. Exactly.
- 15:07But some could also mean 10 percent. Yeah. If
- 15:11some means only the newest accounts created in
- 15:13the last year were hashed. Yeah. And 90 percent
- 15:15of the legacy database was just sitting there
- 15:17in plain readable text for anyone to download.
- 15:19I mean, that is a catastrophic failure of basic
- 15:22security hygiene. So by using this vague language,
- 15:25they get to sound super reassuring to the press
- 15:27while essentially leaving their own users completely
- 15:30in the dark about how fast they actually need
- 15:32to be changing their banking passwords. Because
- 15:34silence matters immensely in cybersecurity. Transparency
- 15:39isn't just about issuing an apology. An apology
- 15:41does not secure a network. True transparency
- 15:44is about providing actionable technical intelligence
- 15:47to the victims so they can protect themselves.
- 15:50Vague reassurance actively erodes trust because
- 15:53it signals to the industry that you are either
- 15:55hiding severe negligence or worse, that your
- 15:58own internal IT teams don't actually know the
- 16:01extent of the damage yet. Specific honest detail,
- 16:04even when the news is objectively terrible. builds
- 16:07trust. It empowers the customer. Okay, so as
- 16:09we pull all of these threads together, let's
- 16:11recap the real journey of this deep dive. Because
- 16:13the KDDI breach of June 2026, it is so much more
- 16:17than just a story about a software bug. It really
- 16:19is a masterclass in evaluating the blast radius
- 16:21of shared infrastructure. Exactly. We've seen
- 16:24how that relentless drive for digital efficiency
- 16:26breeds massive concentration risk. We've explored
- 16:29the cascading dangers of credential stuffing
- 16:31and how our bad password habits basically fuel
- 16:34the fire. And finally, we've seen why the absolute
- 16:37necessity of transparent, specific crisis communication
- 16:41is so critical. It's a stark warning, really,
- 16:44for everyone. it is and there is incredibly actionable
- 16:48advice here for you listening right now the kinsoft
- 16:52analysis strongly suggests taking time to map
- 16:55out your own single points of failure look at
- 16:57your vendors look at your software stack where
- 17:00is your concentration risk quietly hiding. It's
- 17:03always hiding somewhere. Always. And if you need
- 17:05a starting point for that kind of audit, Kinsoft
- 17:07actually offers great resources for mapping this
- 17:09stuff out at kinsoft .com .au. Their core mantra
- 17:12for this is really one we should all adopt. Stay
- 17:14patched, stay skeptical. And I would just add
- 17:17a quick point regarding consumer empowerment.
- 17:19When a service provider you use is breached,
- 17:22and let's be real, statistically speaking, you're
- 17:24going to be caught in one of these eventually,
- 17:26do not settle for the boilerplate PR email assuring
- 17:29you that they, quote, Take your security seriously.
- 17:33I hate that phrase. Right. You are fully entitled
- 17:36to ask planted questions. Demand the technical
- 17:38truth. Was the data encrypted? What specific
- 17:41cryptographic algorithm was utilized? Were the
- 17:44passwords salted? Don't let them hide behind
- 17:46vague words like some. Demand the specifics so
- 17:50you can accurately gauge your own risk. Which
- 17:52leaves us with a final lingering thought to ponder
- 17:55as we wrap up today. We've seen that our digital
- 17:57economy is entirely driven by consolidation.
- 17:59Sharing servers. Centralizing identity access.
- 18:03Rolling multiple brands into single back -end
- 18:05platforms. forms, right? It all drives operational
- 18:07efficiency. But as we continue to centralize
- 18:10more and more of our digital lives into fewer
- 18:12and fewer massive interconnected hubs, are these
- 18:15cascading catastrophic failures simply the unavoidable
- 18:18tax we must pay for modern convenience? Or as
- 18:21the blast radius of these breaches continues
- 18:23to grow, is it time to start intentionally building
- 18:25a little bit of inefficiency and isolation back
- 18:27into our systems?