SHINDO5
IIJ
Internet Initiative Japan Inc.
Personal dataup to4.1Maccounts
LEAK CONFIRMEDPassword / API key / private keyUnauthorized access · Contained
Open in the live monitor ▶- Disclosed
- Apr 15, 2025
- Detected
- Apr 10, 2025
- Detection to disclosure
- 5 days
- Leak
- Leak confirmed
- Type
- Unauthorized access
- Status
- Contained
- Security spend
- Not checked yet
- Compensation
- Not announced
What leaked
ContactMail account (address)
CredentialsPassword, Credentials for third-party cloud services
Communications & contentEmail body, Email header information
How many
- Mail accounts (maximum scope in first report) up to 4.1M accounts
- Customer contracts in scope (first report) up to 6,493 organizations
- Customer contracts with confirmed leaks (second report) 586 organizations
- Mail accounts and passwords (132 contracts) 311,288 accounts
- Contracts whose mail bodies and headers leaked 6 organizations
- Contracts whose third-party cloud credentials leaked 488 organizations
Who is affected
- Corporate customers of IIJ Secure MX
- Mail account users at customer organizations
- Senders and recipients of email
Cause
Attackers exploited a stack-based buffer overflow in Qualitia's Active! mail (CVE-2025-42599, CVSSv3 9.8) used inside the service. Using living-off-the-land techniques with tools already on the system, they went undetected for about eight months
Timeline
- Intrusion began
- Found malicious program execution and began contacting customers
- First disclosure
- Second report (confirmed leaks identified)
- Administrative guidance from the Ministry of Internal Affairs and Communications
What you should do
- Change this password and every account that reused it now. Switch to a passkey where offered
- Don't open links in emails from this company. The apology email itself may be fake
- You can be affected without ever using this service (parcel recipients etc.). Check any notice you receive
- Check the company's notice to see if you're affected
Lessons for companies
- Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
- Never sit on a known defect. Test every change before production
- Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
- Run red teaming and AI-assisted hardening, and publish how much you invest
Sources
- piyolog Researcher · May 31, 2025
- Internet Initiative Japan Inc. (first report) Official notice · Apr 15, 2025
- Internet Initiative Japan Inc. (second report) Official notice · Apr 22, 2025
- Internet Initiative Japan Inc. Official notice · Jul 18, 2025