A data breach at Japanese telecom company KDDI may have exposed the email addresses and passwords of up to 14.2 million accounts across six internet service providers (ISPs).
According to KDDI, hackers gained access by exploiting a vulnerability in third-party software used by one of its email systems. The company says it blocked the attackers after discovering the breach and is working with the affected ISPs to improve security.
The exact number of affected accounts is still being investigated. KDDI also said some passwords were stored in hashed or encrypted form, but it did not specify how many.