Japanese telecommunications company KDDI is facing a major cybersecurity incident, revealing that up to 14.22 million email addresses and passwords may have been exposed after unauthorized access to a shared email service infrastructure. The incident is already among the largest data breaches to affect Japan's internet service industry in recent years.

According to the company, the suspicious activity was detected on June 17, 2026, when security mechanisms recorded access to an email system serving multiple Internet Service Providers (ISPs). KDDI immediately proceeded to contain the incident, modify the affected environment and activate additional protection measures, after first identifying the potential entry point exploited by the perpetrators.
See also: Proton Data Breach Observatory: Notifies you when your personal data appears on the Dark Web
Third-party software vulnerability at the heart of the attack
The company indicates that the breach is linked to software third-partythat was embedded in the email infrastructure. Exploitation of these weaknesses appears to have allowed attackers to gain access to data related to the management of users' mailboxes.
The case highlights a growing problem in cybersecurity: organizations’ reliance on complex software chains and external vendors. Even when an organization has strong security controls in place, a weakness in a third-party system can create a dangerous “window” for cybercriminals.
Six providers and millions of users affected
The incident affected email services operated by six different internet providers: STNet, JCOM, Nifty, Biglobe, Chubu Telecommunications and KDDI Web Communications.
The services at the center of the investigation include: Pikara Hikari Service, Pikara Mobile Service, Oshigoto Pikara Service, CPI rental server email services, J:COM NET, Commufa Hikari, Business Commufa, @nifty Mail, and BIGLOBE Mail, which serve millions of private and business users in Japan.
According to KDDI, the data that may have been exposed includes email addresses and passwords associated with both active and inactive accounts. The number of 14.22 million records is a worst-case scenario, as investigations are still ongoing.
See also: Council of Europe investigates ShinyHunters data breach allegations

The company clarified that some of the passwords were stored in hashed or encrypted form. However, even in these cases, the risk of misuse of the data cannot be ruled out, especially if users reuse the same passwords across multiple services.
Password reset and risk mitigation measures
KDDI has already initiated coordinated actions with the affected providers in order to inform customers and initiate the process password change.
At the same time, the company's security teams continue to analyze the digital traces of the incident, while additional protection measures have been implemented at the level of systems and procedures.
Experts point out that changing your password alone is not enough. Users are also urged to enable multi-factor authentication (MFA), monitor their accounts for any suspicious activity , and avoid reusing the same credentials across different services.
See also: Infinite Campus: Data breach affects 137,000 school staff accounts
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Japan faces new wave of cyberattacks
The KDDI breach is not an isolated incident. In recent years, Japan has seen a significant increase in attacks targeting both public and private organizations.

According to recent data, 180 personal data breach , affecting more than 30 million people. The majority of these incidents were linked to unauthorized access or malware infections.
At the same time, ransomware attacks continue to be one of the biggest threats to the Japanese economy. Businesses of all sizes have faced disruptions, data loss and severe financial impacts.
The KDDI case is yet another reminder that cybersecurity is no longer just about protecting individual systems, but about shielding entire digital ecosystems. In an environment where infrastructure is increasingly interconnected, a security breach at one vendor can escalate into a crisis that affects millions of users and multiple organizations simultaneously.
