Originally published on satyamrastogi.com

KDDI's breach via zero-day in third-party email system demonstrates supply chain attack methodology targeting telecom infrastructure. 12M impacted via ISP email access compromise.

KDDI Zero-Day Supply Chain Attack: 12M ISP Email Compromise

Executive Summary

KDDI Corporation's breach affecting 12 million customers represents a textbook supply chain attack vector: exploitation of a zero-day vulnerability in third-party email infrastructure supporting ISP operations. From an offensive perspective, this incident reveals critical gaps in telco security posture around third-party system isolation and email authentication controls.