Find notable cyber news and cases, enriched with sources, timelines, and signals.
Data Leak Incident

KDDI Multi-ISP Email Credential Exposure in Japan

Updated 24.06.2026 15:45
Case score 75
Case score 75 Members 2 Latest activity 24.06.2026 15:45
Members 2 First seen 24.06.2026 15:45 Last seen 24.06.2026 15:45 Updated 24.06.2026 15:45

Overview

KDDI disclosed unauthorized access to **its email system** used by six Japanese ISPs after detecting the intrusion on **June 17**. The company said an actor exploited a vulnerability in **third-party software** and that **up to 14.22 million** email addresses and passwords were likely compromised, creating immediate account-security risk for customers of the affected providers. KDDI says it has modified the system, applied technical countermeasures, notified Japanese authorities, and urged affected users to **change passwords**. Public details still do not identify the vulnerable software, a CVE, or the intrusion actor, so response is focused on credential hygiene and containment rather than product-specific patch tracking.

Signals

8 derived
Impact signals
Affected impact
Exposed data
Victims/regions
Victim region Japan Sector telecommunications
Status
Incident status Contained
Threat context
Actor unauthorized actor
Data exposure
Data Passwords Leak status Claimed/Sample Only Data Email Addresses

Member happenings

2 related
Data Leak KDDI email-system credential leak affecting Japanese ISPs
Updated 24.06.2026 15:45 Lead Contribution 75
Data Type Passwords Data Type Email Addresses Data Status Claimed/Sample Only

A **KDDI** email-system breach exposed customer credentials across **six Japanese ISPs**, putting **up to 14.22 million** email addresses and passwords at risk. The compromise was detected on **June 17** and publicly disclosed on **June 23**, making this a large-scale credential-exposure event. KDDI says it has **modified the system** and is urging affected customers to **change passwords**.

Incident KDDI Corporation hit by network compromise
Updated 24.06.2026 15:45 Context
Extortion None Incident Contained

**KDDI Corporation** confirmed an **email-system breach** that exposed customer credentials across **six Japanese ISPs**, putting account access at risk. The intrusion was detected on **June 17** and publicly disclosed on **June 23**. KDDI said as many as **14.22 million email addresses and passwords** were likely compromised, making password resets urgent.