← KDDI

2026 KDDI — ISP email-system breach; 12.23M emails, 7.62M passwords across five Japanese ISPs

2026 12.2M records affected Share on X

Data compromised

12,233,087 email addresses and 7,616,173 passwords for current, former, and inactive ISP mail accounts across STNet, JCOM, Chubu Telecommunications, NIFTY, and BIGLOBE; some passwords hashed/encrypted per KDDI July 2026 update

Technical writeup

Verified breach — disclosed June–July 2026. KDDI Corporation said attackers exploited a zero-day flaw in third-party software on an email system KDDI operates for five Japanese ISP partners, with unauthorized access beginning May 16, 2026. KDDI detected the incident June 17, 2026, blocked the attacker, and notified Japan's Personal Information Protection Commission and Ministry of Internal Affairs and Communications. A July 6–8, 2026 company update refined scope: attackers obtained 12,233,087 email addresses and 7,616,173 passwords; KDDI is forcing password resets for affected accounts and deployed endpoint detection and response tooling after a June 23 forensic audit confirmed the vulnerability was patched. Earlier disclosures cited an upper bound of up to 14.22 million address/password pairs including inactive accounts. BreachHistory indexes KDDI's attested 12,233,087 email-address figure.

Root cause

Unauthorized access via zero-day vulnerability in third-party software on KDDI email platform; intrusion began May 16, 2026; detected and blocked June 17, 2026

References