NTT Communications breach exposed data on nearly 18,000 corporate customers
- Organization
- NTT Communications Corporation
- Exploit
- Hacking
- Industry
- Telecommunications
NTT Communications Corporation, the enterprise services arm of Japan's NTT group, disclosed in March 2025 that an intruder had reached a system holding details on 17,891 corporate customers. The company identified the compromised platform as its Order Information Distribution System.
NTT said it detected the unauthorised access on 5 February 2025 and confirmed the following day that information had been taken out of the network. Access to the affected system was blocked on 6 February. The continuing investigation established on 15 February that the attacker had moved to another device inside NTT's network, and that device was disconnected the same day.
The exposed records included customer company names, the names of designated representatives, contract numbers, telephone numbers, email addresses, physical addresses and details of the services each organisation used. NTT said no individual consumer data was involved and that corporate mobile contracts handled by NTT Docomo were not affected.
The company published a notice on its website rather than writing to each affected organisation. BleepingComputer reported that NTT said it would not send personalised notifications to impacted customers, while Security Affairs reported the company had said it would notify affected customers. NTT said it was reviewing the cause and strengthening its security measures. The disclosure followed a distributed denial of service disruption to NTT services in January 2025 and an earlier breach in 2020 that reached 621 companies.