KDDI Corporation hit by network compromise
Incident
Summary
Hide ▲
Show ▼
KDDI Corporation confirmed an email-system breach that exposed customer credentials across six Japanese ISPs, putting account access at risk. The intrusion was detected on June 17 and publicly disclosed on June 23. KDDI said as many as 14.22 million email addresses and passwords were likely compromised, making password resets urgent.
Cases
Related Happenings
KDDI email-system credential leak affecting Japanese ISPs
Data Leak
H score98
First: 24.06.2026 15:45
Last: 24.06.2026 15:45
Sources 1
How related:
Specifically, KDDI said up to 14.22 million email addresses and passwords have likely been compromised.
About this happening:
A KDDI email-system breach exposed customer credentials across six Japanese ISPs, putting up to 14.22 million email addresses and passwords at risk. The compromise was...
KDDI email-system credential leak affecting Japanese ISPs
Data LeakHow related: Specifically, KDDI said up to 14.22 million email addresses and passwords have likely been compromised.
About this happening: A KDDI email-system breach exposed customer credentials across six Japanese ISPs, putting up to 14.22 million email addresses and passwords at risk. The compromise was...
Kimsuky QR-code spear-phishing campaign against think tanks and government entities
Campaign
H score42
First: 09.01.2026 07:46
Last: 09.01.2026 07:46
Sources 1
About this happening:
The FBI warned that Kimsuky (APT43) is running a QR-code spear-phishing campaign that targets think tanks, academic institutions, and U.S. and foreign government ent...
Kimsuky QR-code spear-phishing campaign against think tanks and government entities
CampaignAbout this happening: The FBI warned that Kimsuky (APT43) is running a QR-code spear-phishing campaign that targets think tanks, academic institutions, and U.S. and foreign government ent...
Timeline
-
08.07.2026 14:24 1 articles · 7d ago
KDDI email platform breached via zero-day on May 16
Exploitation ObservedAttackers breached the KDDI email platform used by five Japanese ISPs on May 16 after exploiting a zero-day vulnerability in third-party software, exposing email addresses and passwords across the affected service providers.
Show sources
- Telco giant KDDI says data breach affects over 12 million people — www.bleepingcomputer.com — 08.07.2026 14:24
-
24.06.2026 15:45 1 articles · 21d ago
KDDI detects intrusion in email system used by Japanese ISPs
Detection Ioc UpdateKDDI detected unauthorized access to an email system it provides to several Japanese ISPs on June 17 and assessed that the intrusion exploited a vulnerability in third-party software, putting customer email data at risk.
Show sources
- KDDI Breach Affects Six Japanese ISPs, Exposes 14.2 Email Credentials — www.infosecurity-magazine.com — 24.06.2026 15:45
-
24.06.2026 15:45 2 articles · 21d ago
KDDI confirms breach affecting six Japanese ISP email services
Initial DisclosureKDDI publicly confirmed on June 23 that an unauthorized actor had gained access to the email system it provides to several Japanese ISPs, said up to 14.22 million email addresses and passwords were likely compromised, and identified STNet, KDDI Web Communications, JCOM, Chubu Telecommunications, Nifty Corporation, and Biglobe as affected providers.
Show sources
- KDDI Breach Affects Six Japanese ISPs, Exposes 14.2 Email Credentials — www.infosecurity-magazine.com — 24.06.2026 15:45
- KDDI Breach Affects Six Japanese ISPs, Exposes 14.2 Email Credentials — www.infosecurity-magazine.com — 24.06.2026 15:45
-
24.06.2026 15:45 2 articles · 21d ago
KDDI contains compromised email system and notifies Japanese authorities
Mitigation Patch UpdateOn June 23 KDDI modified the email system to prevent further damage, implemented technical countermeasures at suspected compromised locations, notified the Personal Information Protection Commission and Japan’s Ministry of Internal Affairs and Communications, and urged customers of the affected email services to change their passwords.
Show sources
- KDDI Breach Affects Six Japanese ISPs, Exposes 14.2 Email Credentials — www.infosecurity-magazine.com — 24.06.2026 15:45
- Data breach exposes up to 14.2 million email logins at six ISPs — www.bleepingcomputer.com — 28.06.2026 17:13