KDDI Data Breach Impacts up to 14.2 Million Email Accounts at Six ISPs

2026-06-28T20:51:47Z2409d2b9a5179968b9c506a62508becf65fa1314865268decac41f6aa9ff9e14
APTCISA-KEVDirtyCloneKDDILinux-kernelcryptocurrency-theftdata-breachemail-compromisephishingsignal-recovery-keysthird-party-breachvulnerability-management

What happened

Multiple high-impact security incidents and research items: KDDI disclosed a breach that exposed up to 14.2 million email accounts across six Japanese ISPs after attackers exploited a third‑party software vulnerability. Polymarket suffered a third‑party compromise that enabled malicious code injection and ~$2.94M in crypto theft. JFrog published a working exploit for DirtyClone (Linux kernel privilege escalation, CVE-2026-43503, CVSS 8.8). CISA added Cisco/PTC flaws (including CVE-2026-12569) to its Known Exploited Vulnerabilities catalog. Additional coverage includes FBI/CISA warnings about S

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
2409d2b9a5179968b9c506a62508becf65fa1314865268decac41f6aa9ff9e14
Enrichment time
2026-06-28T20:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · KDDI Data Breach Impacts up to 14.2 Million Email Accounts at Six ISPs · Baitaphish