Dev.to
7/10/2026

The original headline is: "KDDI Zero-Day Supply Chain Attack: 12M ISP Email Compromise"
Original: KDDI Zero-Day Supply Chain Attack: 12M ISP Email Compromise
Short summary
A security analysis of the KDDI breach where a zero-day in third-party email infrastructure compromised 12 million ISP customer accounts. The attacker exploited unpatched legacy software, moved laterally via service account privileges, and established persistence through email forwarding rules and hidden SMTP accounts. The article maps the attack to MITRE ATT&CK techniques and highlights systemic gaps in telco third-party isolation.
- •Zero-day in third-party email system compromised 12M KDDI ISP customer accounts
- •Attacker exploited legacy software, moved laterally via service accounts, and established persistent email access
- •Maps to MITRE ATT&CK T1190 and T1548; highlights telco gaps in third-party isolation and patch management
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



