Find notable cyber news and cases, enriched with sources, timelines, and signals.

KDDI email-system credential leak affecting Japanese ISPs

Data Leak
First reported
Last updated
Happening score
H score 75
1 unique sources, 1 articles

Summary

Hide ▲

A KDDI email-system breach exposed customer credentials across six Japanese ISPs, putting up to 14.22 million email addresses and passwords at risk. The compromise was detected on June 17 and publicly disclosed on June 23, making this a large-scale credential-exposure event. KDDI says it has modified the system and is urging affected customers to change passwords.

Cases

Related Happenings

KDDI Corporation hit by network compromise

Incident
H score71 First: 24.06.2026 15:45 Last: 24.06.2026 15:45 Sources 1

How related: In a public statement released on June 23, KDDI Corporation said an unauthorized actor unlawfully gained access to an email system it provides to several Japanese ISPs, meaning that data linked to customers of these email services may have leaked.

About this happening: **KDDI Corporation** confirmed an **email-system breach** that exposed customer credentials across **six Japanese ISPs**, putting account access at risk. The intrusion was detecte...

Askul records leak tied to RansomHouse ransomware attack

Data Leak
H score49 First: 16.12.2025 01:13 Last: 16.12.2025 01:13 Sources 1

About this happening: The **Askul Corporation** data leak now matters because **RansomHouse** stole about **740,000 records** from the company’s **October** ransomware attack, expanding the blast radiu...

Nikkei Inc. Slack data leak exposing 17,368 users' names, email addresses, and chat histories

Data Leak
H score35 First: 06.11.2025 00:16 Last: 06.11.2025 00:16 Sources 1

About this happening: **Nikkei Inc.** disclosed a **Slack data leak** affecting **17,368** registered users, exposing names, email addresses, and chat histories. The leak followed an **unauthorized ext...

Timeline

  1. 24.06.2026 15:45 1 articles · 5h ago

    Unauthorized access detected in KDDI email system

    Exploitation Observed

    KDDI detected unauthorized access to an email system it provides to several Japanese ISPs and assessed that the actor exploited a vulnerability in third-party software used in the email system.

    Show sources
  2. 23.06.2026 03:00 2 articles · 1d ago

    KDDI confirms breach exposing up to 14.22 million email credentials across six Japanese ISPs

    Initial Disclosure

    KDDI publicly confirmed the breach, said up to 14.22 million email addresses and passwords were likely compromised across six Japanese ISPs, notified the Personal Information Protection Commission and Japan’s Ministry of Internal Affairs and Communications, and urged affected customers to change passwords while countermeasures were being implemented.

    Show sources