Visualização de leitura
Japan’s Aflac, KDDI, Sapporo, Nidec: Four Breaches, One Common Entry Point

Four major Japan cyberattacks reported within two weeks point to a common trend, with attackers gaining access through subsidiaries and third-party infrastructure rather than corporate headquarters. While the incidents affected companies from different industries, including insurance, telecommunications, brewing, and manufacturing, the breaches shared one notable characteristic.
Rather than directly compromising corporate headquarters, attackers gained access through subsidiaries, overseas operations, or third-party infrastructure.
The affected organizations include Aflac Japan, KDDI, Sapporo Holdings, and Nidec, each of which reported separate cyber incidents during the second half of June 2026. Although the attacks involved different circumstances, the disclosures point to an expanding attack surface that extends well beyond an organization's primary network.
Aflac Japan Breach Exposed Customer Data
Aflac Japan disclosed on June 30 that attackers accessed its Japanese operations between June 15 and June 25. According to the company, approximately 4.38 million customers and agents were affected, with a subset of records including bank account information used for insurance premium payments.
The insurer stated that the incident was limited to its Japanese business and did not affect its U.S. operations.
While the company has not attributed the attack to any specific threat group, the reported tactics resemble social engineering techniques previously associated with Scattered Spider.
KDDI Incident Impacts Millions Through Shared Platform
Telecommunications provider KDDI reported unauthorized access involving an email platform used by multiple Japanese internet service providers.
The company said the incident stemmed from a vulnerability in third-party software, potentially exposing up to 14.22 million email account records across six ISPs.
The breach demonstrates how a single vulnerability within shared infrastructure can affect multiple organizations simultaneously.
Sapporo Holdings and Nidec Target Overseas Subsidiaries
Sapporo Holdings disclosed suspected unauthorized access involving two overseas subsidiaries, Singapore-based Pokka and Canadian brewer Sleeman. The company detected suspicious activity, shut down affected systems, and launched an investigation to determine whether any information had been accessed or stolen.
Meanwhile, manufacturing company Nidec confirmed a ransomware attack targeting its Taiwanese subsidiary, Nidec Chaun Choung Technology.
The BlackField ransomware group claimed responsibility for the attack, alleging it had stolen more than two terabytes of company data, including employee, financial, procurement, manufacturing, legal, and IT records. The group reportedly demanded a $2 million ransom.
A Shared Pattern Across the Japan Cyberattacks
Despite involving different industries and attack methods, the four Japan cyberattacks reveal a similar point of compromise.
Aflac's breach was limited to its Japanese business. KDDI's exposure originated from a shared email platform relying on vulnerable third-party software. Sapporo's investigation centers on overseas subsidiaries, while Nidec's ransomware incident affected its Taiwan-based operation rather than its headquarters.
These cases suggest attackers are increasingly targeting subsidiaries, shared services, overseas business units, and technology partners instead of attempting to breach an organization's primary corporate network.
Growing Risks Across the Extended Enterprise
The incidents highlight the importance of treating subsidiaries and external partners as part of the organization's overall security perimeter.
Organizations that rely on overseas offices, acquired businesses, vendors, or shared platforms may inherit additional cybersecurity risks if those environments are not protected to the same standard as corporate headquarters.
The KDDI incident illustrates how third-party dependencies can significantly increase the scale of a breach, while the Nidec cyberattack demonstrates how ransomware groups continue to combine data theft with extortion demands.
The reported tactics observed in the Aflac incident also reinforce the continued effectiveness of social engineering as an initial access method.
While investigations into several of the incidents remain ongoing, the recent disclosures underscore a broader trend. As enterprise environments become increasingly interconnected, subsidiaries, shared infrastructure, and external technology providers are becoming attractive targets for attackers seeking indirect access to larger organizations.
Japanese Telecom Giant Says Breach May Expose 14.2 Million Email Accounts
KDDI says a breach may have exposed email addresses and passwords for up to 14.2 million ISP accounts across six providers.
The post Japanese Telecom Giant Says Breach May Expose 14.2 Million Email Accounts appeared first on TechRepublic.
KDDI Data Breach Impacts up to 14.2 Million Email Accounts at Six ISPs
KDDI Corporation disclosed a breach affecting up to 14.2 million email accounts after attackers exploited a vulnerability in third-party software.
KDDI Corporation disclosed a data breach that exposed up to 14.2 million email accounts across six Japanese internet service providers.
KDDI Corporation is one of Japan’s largest telecommunications companies. It employs more than 60,000 people and generates annual revenue of roughly ¥5.9 trillion (about US$40 billion). The company provides mobile, fixed-line, broadband, cloud, data center, IoT, and digital services, operating primarily in Japan while serving enterprise customers across Asia and other international markets.
The company detected the intrusion on June 17, quickly blocked the attackers, and launched an investigation. According to KDDI, the breach was caused by a vulnerability in third-party software used by its email system. The company is continuing its investigation while assessing the full impact of the incident.
“On June 17, 2026, we confirmed that some information from email services provided by various ISP operators (hereinafter referred to as “the email service”) may have been leaked to an external party in the email system (hereinafter referred to as “the System”) that we provide to Internet Service Providers (hereinafter referred to as “ISP operators”).” reads the data breach notice.
“On the same day, we modified the System to prevent further damage. We have identified the suspected location of the Unauthorized Access and implemented technical defense measures.”
KDDI said it has reported the breach to Japan’s privacy and telecommunications regulators and is taking the required legal and regulatory steps. The incident affected the email services of six internet providers: STNet, KDDI Web Communications, JCOM, Chubu Telecommunications, Nifty, and BIGLOBE.
The company confirmed said that email addresses and passwords may have been exposed, including accounts belonging to former and inactive customers. While passwords were stored in hashed or encrypted form, the company warned they may have been obtained by attackers. KDDI is coordinating response efforts, and is urging all impacted users to change their email passwords immediately to reduce the risk of unauthorized access.
“We are also proceeding with discussions and implementation of countermeasures. While we have implemented technical security measures for this system, there is a possibility that your email address and password may have been illegally obtained by a third party due to this unauthorized access.” concludes the notice. “To ensure the protection of your data and eliminate future and potential risks, you will need to change your email password. We ask that you check the information provided by your ISP provider and take immediate action. We will continue to work with ISP providers to inform customers and take appropriate action to encourage prompt password changes.”
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, data breach)
KDDI Data Breach May Have Exposed Up to 14.22 Million Email Accounts
