People search KDDI data breach timeline because the brand sits on billions of accounts, credentials, and cloud workloads. BreachHistory indexes 3 KDDI-linked incidents (1 company-confirmed), with headline counts up to 14.2M+ in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.
Why KDDI breach history matters
KDDI operates in Technology (Japan). Across indexed rows, recurring themes include third-party and supply-chain exposure, zero-day exploitation and malware. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.
Full timeline through 2026
2026 — ISP email-system breach; up to 14.22M addresses/passwords across six Japanese providers
Verified breach. KDDI Corporation disclosed June 2026 that threat actors gained unauthorized access to an email system KDDI operates for five Japanese ISP partners. KDDI detected the incident June 17, 2026, blocked the attacker, and patched a third-party software vulnerability exploited in the intrusion. The company warns up to 14.22 million customer email addresses and passwords may have been obtained—including current, former, and inactive accounts across STNet, JCOM, Chubu Telecommunications, NIFTY, and BIGLOBE. KDDI states some Exposed categories include Up to 14.22 million email addresses and passwords for current, former, and inactive ISP mail accounts across STNet, JCOM, Chubu Telecommunications, NIFTY, and BIGLOBE services; som. BreachHistory cites approximately 14.2M+ affected records in this row. See the kddi-isp-email 2026 record and canonical BreachHistory entry.
2010 — — KDDI: Press report: Tokyo police have arrested two men…
Unverified claim — treat actor counts cautiously. Press report: Tokyo police have arrested two men for trying to extort nearly US$90,000 from KDDI Corp. The pair allegedly threatened to disclose the existence of storage media containing personal data belonging to four million KDDI customers prior to a shareholder meeting; however, KDDI alerted the police as soon as they were contacted by the blackmailers; the police monitored communications between KDDI and the pair for several weeks. BreachHistory cites approximately 4M+ affected records in this row. See the kddiu and canonical BreachHistory entry.
2006 — — KDDI: Press report: Tokyo police have arrested two men…
Unverified claim — treat actor counts cautiously. Press report: Tokyo police have arrested two men for trying to extort nearly US$90,000 from KDDI Corp. The pair allegedly threatened to disclose the existence of storage media containing personal data belonging to four million KDDI customers prior to a shareholder meeting; however, KDDI alerted the police as soon as they were contacted by the blackmailers; the police monitored communications between KDDI and the pair for several weeks. BreachHistory cites approximately 4M+ affected records in this row. See the kddi2006 and canonical BreachHistory entry.
Patterns and analysis
- Third-party and supply-chain exposure — appears across multiple KDDI catalog entries; prioritize controls that address this class of failure.
- Zero-day exploitation and malware — appears across multiple KDDI catalog entries; prioritize controls that address this class of failure.
- Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
- 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.
What to do if you may be affected
- Step 1: Enable phishing-resistant MFA on every account tied to this brand.
- Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
- Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
- Step 4: Review OAuth app permissions and revoke unused third-party integrations.
- Step 5: Bookmark the KDDI company page for new 2026+ disclosures.
Canonical BreachHistory hub
Explore every indexed row: breachhistory.com/kddi · Latest: kddi-isp-email2026.
Sources: BreachHistory catalog (3 rows for KDDI), company and regulator disclosures cited in individual breach records.