SHINDO5

IIJ

Personal dataup to4.1Maccounts

LEAK CONFIRMEDPassword / API key / private keyUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Apr 15, 2025
Detected
Apr 10, 2025
Detection to disclosure
5 days
Leak
Leak confirmed
Type
Unauthorized access
Status
Contained
Security spend
Not checked yet
Compensation
Not announced

What leaked

ContactMail account (address)
CredentialsPassword, Credentials for third-party cloud services
Communications & contentEmail body, Email header information

How many

  • Mail accounts (maximum scope in first report) up to 4.1M accounts
  • Customer contracts in scope (first report) up to 6,493 organizations
  • Customer contracts with confirmed leaks (second report) 586 organizations
  • Mail accounts and passwords (132 contracts) 311,288 accounts
  • Contracts whose mail bodies and headers leaked 6 organizations
  • Contracts whose third-party cloud credentials leaked 488 organizations

Who is affected

  • Corporate customers of IIJ Secure MX
  • Mail account users at customer organizations
  • Senders and recipients of email

Cause

Attackers exploited a stack-based buffer overflow in Qualitia's Active! mail (CVE-2025-42599, CVSSv3 9.8) used inside the service. Using living-off-the-land techniques with tools already on the system, they went undetected for about eight months

Timeline

  1. Intrusion began
  2. Found malicious program execution and began contacting customers
  3. First disclosure
  4. Second report (confirmed leaks identified)
  5. Administrative guidance from the Ministry of Internal Affairs and Communications

What you should do

  1. Change this password and every account that reused it now. Switch to a passkey where offered
  2. Don't open links in emails from this company. The apology email itself may be fake
  3. You can be affected without ever using this service (parcel recipients etc.). Check any notice you receive
  4. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Never sit on a known defect. Test every change before production
  3. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  4. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources