---
schema_version: '1.0'
id: news-20260706-353c11
url: https://gotosocial.chinng-lab-srv.dev/kddi-760mo-ren-fen-nopasuwadoliu-chu-gaque-ding-ispmerusisutemubu-zheng-akusesugatu-kitukeru-sadopateicui-ruo-xing-toiusi-jiao/
url_hash: 353c11d32336413ffe51458a60ce309e6d9c18a98fba16b6aa864b08d6b4e454
canonical_url: https://gotosocial.chinng-lab-srv.dev/kddi-760mo-ren-fen-nopasuwadoliu-chu-gaque-ding-ispmerusisutemubu-zheng-akusesugatu-kitukeru-sadopateicui-ruo-xing-toiusi-jiao
source: ghost-chinng-lab
category: news/tech
category_raw: AI・テクノロジー
region: JP
tags:
- AI・テクノロジー
- KDDI確認
- パスワード漏洩
- ISPメール
- セキュリティレベル
- 漏洩確認
lang: ja
published_at: '2026-07-06T11:42:47Z'
fetched_at: '2026-07-06T12:08:09Z'
updated_at: '2026-07-06T12:08:39Z'
status: published
content_hash: null
license_note: full
summary: KDDIが提供するISP向けメールシステムへの不正アクセスで、約1223万件のメールアドレスと761万件のパスワード漏洩が確定した。原因は組み込みソフトウェアのゼロデイ脆弱性で、ベンダー自身も当初把握していなかった。@nifty、BIGLOBE、J:COMなど6社のサービスが影響を受け、BtoB委託構造による「見えないリスク」が消費者に直結した典型例となった。同時期の他社漏洩事案と合わせると、複雑な委託・提携関係が通信インフラ全体の構造的な脆弱性を示している。
summary_source: llm
summary_en: KDDI's unauthorised access to the ISP mail system has confirmed about
  1223 million email addresses and 761 million password leaks. The cause was zero-day
  vulnerability of embedded software, and theソフトウェア didn’t know it. This is a typical
  example of “invisible risks” directly connected to consumers by the BtoB consignment
  structure, which includes six services such as @nifty, BIGLOBE, and J:COM. In  with
  other companies' leaks at the same time, complex consignment and partnerships indicate
  structural vulnerabilities throughout the communication infrastructure。
entities:
- name: KDDI
  type: organization
- name: European ISPs
  type: organization
key_facts: []
related: []
related_auto:
- name: Rightsholders
  type: organization
  weight: 2.0
- name: AI
  type: concept
  weight: 1.0
- name: ゼロデイ脆弱性
  type: concept
  weight: 1.0
- name: 第三者製ソフトウェア
  type: artifact
  weight: 1.0
- name: サプライチェーンセキュリティ
  type: UNKNOWN
  weight: 1.0
title: KDDI、760万人分のパスワード流出が確定 ― ISPメールシステム不正アクセスが突きつける「サードパーティ脆弱性」という死角
---

# KDDI、760万人分のパスワード流出が確定 ― ISPメールシステム不正アクセスが突きつける「サードパーティ脆弱性」という死角

## TL;DR
KDDIが提供するISP向けメールシステムへの不正アクセスで、約1223万件のメールアドレスと761万件のパスワード漏洩が確定した。原因は組み込みソフトウェアのゼロデイ脆弱性で、ベンダー自身も当初把握していなかった。@nifty、BIGLOBE、J:COMなど6社のサービスが影響を受け、BtoB委託構造による「見えないリスク」が消費者に直結した典型例となった。同時期の他社漏洩事案と合わせると、複雑な委託・提携関係が通信インフラ全体の構造的な脆弱性を示している。

## Key Points
- AI・テクノロジー / KDDI確認 / パスワード漏洩 / ISPメール / セキュリティレベル / 漏洩確認

## Details
(本文なし。リンク先参照)

## Source
元記事: [KDDI、760万人分のパスワード流出が確定 ― ISPメールシステム不正アクセスが突きつける「サードパーティ脆弱性」という死角](https://gotosocial.chinng-lab-srv.dev/kddi-760mo-ren-fen-nopasuwadoliu-chu-gaque-ding-ispmerusisutemubu-zheng-akusesugatu-kitukeru-sadopateicui-ruo-xing-toiusi-jiao/) — published 2026-07-06T11:42:47Z
