Internet Initiative Japan Inc. (IIJ) confirmed a data breach affecting approximately 310,000 email accounts due to a cyberattack exploiting a vulnerability in its Active! mail security service. The breach was linked to a critical buffer overflow flaw identified as CVE-2025-42599, which has been actively exploited in the wild. This vulnerability allowed remote code execution attacks on Japanese organizations using the service. IIJ announced the incident on April 22, 2025, acknowledging the compromise of customer email address information. The company is investigating the scope and impact of the breach while working to mitigate further risks.