KDDI Data Breach History
WebsiteKDDI is a Japanese telecommunications operator providing mobile, fixed-line, and ICT services.
This page shows all data breaches of KDDI. View the complete breach timeline, records exposed, root causes, and AI breach risk score. BreachHistory tracks disclosed data breaches worldwide.
Data Breach Timeline — All KDDI Breaches
- 2026 2026 KDDI — ISP email-system breach; 12.23M emails, 7.62M passwords across five Japanese ISPs 12.2M records Share
- 2010 2010 — KDDI: Press report: Tokyo police have arrested two men… 4.0M records Share
- 2006 2006 — KDDI: Press report: Tokyo police have arrested two men… 4.0M records Share
KDDI Data Breach Summary
This page tracks the KDDI data breach history and cybersecurity incidents affecting KDDI (Japan). BreachHistory currently indexes 3 publicly disclosed or catalogued incidents spanning 2006 through 2026, with approximately 20.2 million records reported as exposed across all indexed events. These totals may include overlapping datasets or third-party estimates and should not be interpreted as unique affected users.
The KDDI breach timeline includes major data breaches, cyber attacks, data leaks, credential exposures, API abuse, and other security incidents. Each incident provides details on the estimated records exposed, attack method, affected data types, and supporting public sources. Currently, 0 incidents are company-confirmed, while 2 remain unverified claims pending independent verification.
Largest KDDI Data Breaches
The largest indexed incidents include the 2026 KDDI — ISP email-system breach; 12.23M emails, 7.62M passwords across five Ja…, the 2010 — KDDI: Press report: Tokyo police have arrested two men…, and the 2006 — KDDI: Press report: Tokyo police have arrested two men…. Record counts originating from threat actors or leak sites should be treated as estimates unless confirmed by KDDI or a regulator. Below is the list of large data breaches:
- 2026 2026 KDDI — ISP email-system breach; 12.23M emails, 7.62M passwords across five Japanese ISPs — about 12.2M records exposed · Catalogued incident
- 2010 2010 — KDDI: Press report: Tokyo police have arrested two men… — about 4.0M records exposed · Unverified claim
- 2006 2006 — KDDI: Press report: Tokyo police have arrested two men… — about 4.0M records exposed · Unverified claim
What Information Was Exposed?
Depending on the incident, exposed data may include email addresses, passwords and login credentials, physical addresses, and other personal information (PII). The exact data varies between incidents, so review each breach page before assuming your information was affected.
KDDI Data Breach 2026
At the time of this update, BreachHistory catalogues 1 2026 incident related to KDDI. Most recent entry: 2026 KDDI — ISP email-system breach; 12.23M emails, 7.62M passwords across five Japanese ISPs. New incidents are added as official disclosures, regulatory filings, or credible cybersecurity reports become available.
What To Do If You Were Affected
If you believe your account may have been involved in a KDDI data breach, change any reused passwords, enable multi-factor authentication (MFA), monitor your account for suspicious activity, and be cautious of phishing emails or fake breach notifications.
This KDDI breach history is maintained by BreachHistory using public disclosures, regulatory filings, security research, and clearly labelled third-party claims. For the complete breach timeline, records exposed, incident details, and AI Breach Risk Score, explore the sections on this page.