← Blog

KDDI Breach: 14.2M Japanese ISP Email Logins Exposed

Share on X

June 28, 2026: Japanese telecom giant KDDI Corporation disclosed that attackers accessed an email system used by five ISP partners, potentially exposing up to 14.22 million email addresses and passwords.

What KDDI confirmed

Per BleepingComputer and KDDI's official notice, KDDI detected unauthorized access June 17, 2026, blocked the attacker, and remediated a vulnerability in unnamed third-party software.

Affected ISP email services:

  • STNet, Inc.
  • JCOM Co., Ltd.
  • Chubu Telecommunications Co., Inc.
  • NIFTY Corporation
  • BIGLOBE Inc.

Scale and password risk

The 14.22 million figure includes current, former, and inactive accounts. KDDI says some passwords were hashed or encrypted—but did not quantify plaintext exposure, leaving account-takeover risk uncertain for affected users.

What to do

  1. Reset ISP email passwords immediately if you use any affected provider.
  2. Enable 2FA where supported.
  3. Never reuse that password on banking or social accounts.

Canonical record: KDDI ISP email breach 2026 on BreachHistory.