Find notable cyber news and cases, enriched with sources, timelines, and signals.
Data Leak Incident

KDDI Multi-ISP Email Credential Exposure in Japan

Updated 08.07.2026 14:24
Case score 75
Members 2 First seen 24.06.2026 15:45 Latest activity 08.07.2026 14:24

Overview

KDDI disclosed unauthorized access to **its email system** used by six Japanese ISPs after detecting the intrusion on **June 17**. The company said an actor exploited a vulnerability in **third-party software** and that **up to 14.22 million** email addresses and passwords were likely compromised, creating immediate account-security risk for customers of the affected providers. KDDI says it has modified the system, applied technical countermeasures, notified Japanese authorities, and urged affected users to **change passwords**. Public details still do not identify the vulnerable software, a CVE, or the intrusion actor, so response is focused on credential hygiene and containment rather than product-specific patch tracking.
Latest development Open development history 3 earlier developments KDDI email platform breached via zero-day on May 16 Attackers breached the KDDI email platform used by five Japanese ISPs on May 16 after exploiting a zero-day vulnerability in third-party software, exposing email addresses and passwords across the affected service providers.
  1. Earlier development

    KDDI contains compromised email system and notifies Japanese authorities

    On June 23 KDDI modified the email system to prevent further damage, implemented technical countermeasures at suspected compromised locations, notified the Personal Information Protection Commission and Japan’s Ministry of Internal Affairs and Communications, and urged customers of the affected email services to change their passwords.

  2. Earlier development

    KDDI confirms breach affecting six Japanese ISP email services

    KDDI publicly confirmed on June 23 that an unauthorized actor had gained access to the email system it provides to several Japanese ISPs, said up to 14.22 million email addresses and passwords were likely compromised, and identified STNet, KDDI Web Communications, JCOM, Chubu Telecommunications, Nifty Corporation, and Biglobe as affected providers.

  3. Earlier development

    KDDI detects intrusion in email system used by Japanese ISPs

    KDDI detected unauthorized access to an email system it provides to several Japanese ISPs on June 17 and assessed that the intrusion exploited a vulnerability in third-party software, putting customer email data at risk.

Signals

Impact signals
Affected impact
Geographic context
Status
Threat context
Data exposure

Technical intelligence

Existing Case data

Member happenings

Data Leak KDDI email-system credential leak affecting Japanese ISPs
Updated 24.06.2026 15:45 Lead Contribution 75
Data Type Passwords Data Type Email Addresses Data Status Claimed/Sample Only

A **KDDI** email-system breach exposed customer credentials across **six Japanese ISPs**, putting **up to 14.22 million** email addresses and passwords at risk. The compromise was detected on **June 17** and publicly disclosed on **June 23**, making this a large-scale credential-exposure event. KDDI says it has **modified the system** and is urging affected customers to **change passwords**.

Incident KDDI Corporation hit by network compromise
Updated 24.06.2026 15:45 Context
Extortion None Incident Contained

**KDDI Corporation** confirmed an **email-system breach** that exposed customer credentials across **six Japanese ISPs**, putting account access at risk. The intrusion was detected on **June 17** and publicly disclosed on **June 23**. KDDI said as many as **14.22 million email addresses and passwords** were likely compromised, making password resets urgent.