HomeSecurityKDDI Breach: 12 million emails and 7.6 million passwords in 6 Japanese...

KDDI breach: 12 million emails and 7.6 million passwords across 6 Japanese ISPs

The KDDI breach is the largest email data breach in Japanese telecommunications history. Japan's second-largest mobile carrier confirmed on July 7, 2026, that 12.23 million email addresses and 7.61 million passwords were exposed to unauthorized third parties through a vulnerability in third-party software that KDDI used to provide email services to six different Japanese internet providers. The incident began in mid-May, was discovered on June 17, and turned a simple third-party vulnerability into a cascading crisis for the entire Japanese ISP map.

KDDI breach 12 million emails leaked Japan

KDDI Corporation, known in the Japanese market for its mobile brands “au” and “UQ mobile,” operates a shared email platform that serves tens of millions of subscribers — not just its own, but also customers of third-party ISPs. This shared infrastructure became the “central point of failure” of the breach: one vulnerability, six providers, simultaneously exposed. According to reports in the Japan Times and BleepingComputer, the company’s initial estimate was up to 14.22 million email/password combinations; the final report to Japan’s Ministry of Internal Affairs narrowed the number to 12.23 million — a figure that fully justifies the “historic” designation for the incident.

Article contents

In the following article, the SecNews editorial team analyzes the KDDI breach in all its dimensions:

• Who is KDDI and what was exposed
• KDDI breach: timeline of the incident
• The six providers affected
• How the supply-chain attack was carried out
• The regulatory response: MIC, PPC, APPI
• The history of Japanese telecommunications
• What every affected user should do
• What it means for Europe and Greece

See also: Charter Communications targeted by ShinyHunters – Data Breach

Who is KDDI and what was exposed?

KDDI Corporation is Japan's second-largest telecommunications group, with annual revenues of over $45 billion and tens of millions of subscribers across mobile, fixed and internet services. It provides the widely recognized "au" brand for mobile telephony, as well as email hosting services for a number of Japanese ISPs that choose to outsource this function to its infrastructure rather than manage it in-house.

The KDDI breach does not concern its own branded email systems (au mail and UQ mobile mail), which operate on separate infrastructure and remained intact. It concerns the shared email platform that KDDI provides as a B2B service to other providers. According to the official announcement published by the company, “on June 17, 2026, we confirmed that certain information from email services provided by various ISPs may have been leaked to external parties through the email system we provide to our ISP customers.”

The data exposed, based on official disclosures, is limited to email addresses and passwords. KDDI has explicitly stated that there is no evidence of a leak of message content, names, home addresses, telephone numbers or financial information. This of course does not mean that the risk is small: a complete email+password package is a goldmine for credential stuffing attacks in banking, e-commerce and social media services where many users reuse the same passwords.

KDDI breach: timeline of the incident

The picture emerging from the intersection of Japanese, English-speaking and Chinese-speaking sources — including the final report that KDDI submitted to the authorities — shows an invasion that remained invisible for more than a month:

May 16, 2026: Estimated start of unauthorized access to the public email system. The attacker exploited a vulnerability in third-party software and began systematic data extraction.

June 17, 2026: KDDI detects the intrusion, applies a patch on the same day, and notifies the Personal Data Protection Commission (PPC) and the Ministry of Internal Affairs and Communications (MIC). The exploitation window has lasted 32 days.

June 21, 2026: The parent company officially informs its 100% subsidiary, KDDI Web Communications (known for its CPI service), that some of its own customers may have been affected.

June 23, 2026: First public announcement — up to 14.22 million email/password combinations may have been exposed, in the worst-case scenario including active, former, and dormant accounts.

KDDI data breach technical email server hack Japan

June 24, 2026: MIC issues formal order to KDDI to file a written report by July 6, under the Telecommunications Business Act (電気通信事業法). Regulatory pressure escalates.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

July 6, 2026: KDDI Web Communications details the number for its own CPI service — 1,250,543 email addresses confirmed exposed (no passwords in this subset) — and announces a mandatory password reset for customers who haven't already changed theirs.

July 7, 2026: KDDI submits the final report and gives the final numbers: 12.23 million email addresses and 7.61 million passwords were indeed accessed without authorization. Minister Yoshimasa Hayashi states at a press conference: "It is extremely regrettable that the incident had a great impact on users."

See also: Ericsson in the US reveals data breach

The six providers affected

One of the most concerning features of the incident is the breadth of its “blast radius.” KDDI operated the shared email system for a total of six different entities — large regional ISPs, cable providers, historical names in Japanese internet, and two of its own subsidiaries. Their shared infrastructure meant that they were all simultaneously “hit” by a single vulnerability.

The first affected company is STNet, Inc., which provides Pikara Hikari, Pikara Mobile, and business Oshigoto Pikara mail services to customers mainly on the island of Shikoku. Second is JCOM Co., Ltd. (known as J:COM), Japan's largest cable TV and internet provider, with its J:COM NET email service. Third is Chubu Telecommunications (CTC), with its Commufa Hikari and Business Commufa mail services covering the Chubu region around Nagoya.

Next is NIFTY Corporation, one of the most historic Japanese ISPs with the @nifty Mail service — a brand that many Japanese users have maintained for decades. On Thursday comes BIGLOBE Inc., a subsidiary of KDDI, with BIGLOBE Mail. Sixth and last is KDDI Web Communications, a 100% subsidiary of parent company KDDI, known for its CPI server rental service aimed at businesses and developers. The difference between “five” and “six” ISPs that appears in some international publications is due to KDDI mentioning the five other providers in addition to its own subsidiary.

How the supply-chain attack was carried out

The technical background of the KDDI breach clearly places the incident in the category of supply chain attacks. The attacker did not directly target the six ISPs; he exploited a vulnerability in third-party software embedded in KDDI's shared email system. Because this system serves multiple customers simultaneously, a single point of weakness translated into simultaneous exposure of all of them.

Two important pieces of information are still missing from the public disclosure: KDDI has not named the vulnerable software or vendor, nor has a specific CVE number been published. This lack of transparency makes it difficult for other organizations that may be using the same software to check whether they are also exposed. Many security analysts are pushing for public disclosure of at least the CVE, if not the vendor name, for this very reason.

The attacker is not publicly known. No ransomware group has claimed the incident, none has listed it on a named leak site, and no official attribution has been made to a state or APT. CybelAngel note, however, that the first quarter of 2026 saw a significant shift in activity by Russian and Chinese actors toward Japanese targets — a context that makes the possibility of state sponsorship realistic, but without this being confirmed for this specific case.

Additionally, KDDI announced plans to use artificial intelligence to analyze software design specifications and identify future problems across its infrastructure. It is also considering a move to more secure communication protocols in collaboration with its ISP customers — a move that, if implemented, could upgrade the security of the entire Japanese email ecosystem.

regulatory investigation Japan MIC PPC KDDI violation

The regulatory reaction: MIC, PPC, APPI

The Japanese regulatory framework was immediately mobilized. KDDI notified the Personal Information Protection Commission (PPC), the independent body equivalent to the European Data Protection Authorities, in accordance with the disclosure obligations of the APPI (Act on Protection of Personal Information). At the same time, the Ministry of Internal Affairs and Communications (MIC) requested a formal written report, as permitted by the Telecommunications Business Act.

The MIC’s move is not routine: the ministry has discretion to impose administrative sanctions, require improved security plans, or, in extreme cases, suspend a license. For a company the size of KDDI, the most likely outcome is a fine and supervised implementation of corrective measures, not a license revocation — but the public pressure from Minister Hayashi shows that the issue is being treated as one of national importance.

In Japan, unlike the US, there is no strong class action mechanism for data breaches. Thus, the main legal consequence is not expected to be class action lawsuits from customers, but administrative fines, compliance with PPC and MIC recommendations, and of course the cost of infrastructure upgrades and compensation to KDDI's ISP customers who saw their reputations damaged.

See also: Lithuania: Foreign country behind leak of 600,000 registry files

The history of Japanese telecommunications

The KDDI breach is part of a worrying pattern of attacks on Japanese telecoms providers. In 2006, KDDI itself suffered one of the country’s first major customer data breaches, with around 4 million “DION” customer records leaked — a shock then, now a third the size of the current incident.

Its biggest competitor, NTT Docomo, has also been repeatedly attacked. In April 2023, a leak was revealed that may have affected 5.29 million records, while in September 2023, the Ransomed.vc group demanded a ransom of over $1 million. On four separate occasions between 2022 and 2025, NTT Docomo suffered DDoS attacks that disrupted webmail, payments, and streaming services. Subsidiary NTT Communications suffered its own breach in February 2025, with 17,891 corporate customers seeing their details (contract numbers, names, phones, emails, addresses) exposed.

The third major Japanese telco, SoftBank, was not spared either: in December 2024 (disclosed in 2025) it suffered a breach through third-party provider UF Japan, with 137,156 SoftBank/Y!Mobile subscribers affected. This string of incidents across providers—with KDDI now adding the largest email/credential leak in Japanese telco history—fully justifies the increased regulatory pressure.

Japan’s fiscal year 2024 saw over 21,000 personal data breaches — a 58% increase from the previous year, with ransomware a key driver. Japanese organizations are expected to experience an average of 1,231 cyberattacks per week in 2025, and the shift in activity by Russian and Chinese actors towards Japan in the first quarter of 2026 makes the landscape even more challenging.

What every affected user should do

While the KDDI breach primarily affects Japanese users, the practical advice it provides is entirely applicable to any credential breach worldwide — and particularly critical for anyone with an email account with any of the six affected providers. The SecNews technical team recommends the following measures in order of priority.

First and foremost: change your email password, even if no personalized notification has been sent by the provider. The scope of the leak allows for unnecessary protection: the password is considered exposed until proven otherwise. In particular, users of STNet/Pikara, J:COM, Chubu Commufa, @nifty, BIGLOBE and CPI should proceed immediately.

Second measure: check for password reuse across other services. If the same email+password combination is used across banking, e-commerce, social media, or cloud services, it should be changed there immediately as well. Credential stuffing—where attackers automatically try leaked credentials across dozens of other services—is currently the most profitable “second life” of breaches like this.

Third: enable multi-factor authentication (MFA/2FA) where available, with preference for an authenticator app or hardware token over SMS. Fourth: increased vigilance for phishing messages that mimic the six providers — attackers now have a valid list of email addresses and ISP names that they can use convincingly.

Fifth and often overlooked: check for dormant accounts. Even if you canceled your subscription years ago, your details are likely still in the leaked data. Spam email addresses that haven’t been actively used can be just as vulnerable as active ones. Sixth: monitor for signs of malicious use — unusual logins, unsolicited password reset messages, targeted phishing that correctly lists personal details.

See also: Ransomware groups turn to Citrix Bleed 2, BYOVD and credential theft

What does it mean for Europe and Greece?

The KDDI breach does not directly concern European or Greek users, but it highlights a risk that makes the European NIS2. At the European level, telecommunications providers have now been classified as “essential entities” and service providers to them (managed service providers, SaaS platforms, cloud email providers) face increased incident notification obligations.

The mathematical equation is simple: the more providers share the same email infrastructure with a common provider, the greater the multiplier risk. The same applies to Greek companies that depend on a common cloud email infrastructure, on common third-party filters, on common MSSP suppliers. A single point of failure at the supplier level can hurt dozens of organizations simultaneously.

For Greek businesses, there are three practical takeaways from the Japanese incident. First, third-party risk management: mapping all dependencies on external software providers and enforcing contractual obligations for immediate notification in the event of an incident. Second, segregation of email infrastructure from other critical services — if the email infrastructure goes down, bank or ERP accounts should not be affected. Third, adopting pass-key or hardware token for admin accounts, so that a stolen password is not enough to keep the attacker in the system for long.

Shared infrastructure is cost-effective but risky when not accompanied by strict isolation, continuous vulnerability scanning, and distributed detection controls. The KDDI breach is the clearest example of this truth recorded at a telecommunications provider in 2026. European authorities are already studying the incident as part of the NIS2 review, and the Greek National Cybersecurity Authority will be called upon to incorporate its lessons into revised guidelines for third-party risk for Greek providers. The next big incident may be closer than we think — and this time it may hit our own internet “neighborhood.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS