AIO APEX

KDDI Breach Exposes 14.2 Million Email Accounts Across Six Japanese ISPs

BleepingComputer
Share:
KDDI Breach Exposes 14.2 Million Email Accounts Across Six Japanese ISPs

KDDI Corporation, Japan's second-largest mobile carrier, disclosed on June 17 that attackers breached its managed email infrastructure, potentially exposing the credentials of up to 14.22 million accounts across six Japanese internet service providers.

The breach is one of the largest data exposures in Japan's recent history, affecting customers of STNet, KDDI Web Communications, JCOM, Chubu Telecommunications, Nifty, and Biglobe — all of which rely on a shared email management platform operated by KDDI.

How the Attack Happened

KDDI's investigation found that the attackers exploited vulnerabilities in third-party software integrated into the shared email system. Once inside, they gained unauthorized access to mailbox account information, including email addresses and the passwords associated with them. The breach was detected on June 17, 2026, and KDDI moved quickly to block the attacker and patch the entry point.

The company notified Japan's Personal Information Protection Commission and the Ministry of Internal Affairs and Communications on the same day it detected the intrusion — a relatively swift response that indicates KDDI had incident response procedures in place.

Who Is Affected

The 14.22 million figure represents the maximum potential exposure and includes current, former, and inactive accounts across all six affected ISPs. Not every account was necessarily accessed, but KDDI has not confirmed which subset was actively breached. The company has urged all users across the six ISPs to change their email passwords immediately, regardless of whether they have received individual notification.

The ISPs involved span major Japanese broadband markets. Nifty is one of the country's oldest ISPs with millions of residential customers. JCOM is a cable television and broadband provider. Biglobe is a well-known consumer ISP owned by KDDI. The shared infrastructure model that made this breach possible — one platform serving multiple operators — is common in Japan's telecom industry, which means a single vulnerability had an outsized impact.

What Was Exposed

KDDI confirmed that email addresses and login passwords were among the exposed data. Whether passwords were stored in plain text, hashed, or encrypted has not been disclosed. If any passwords were stored without strong hashing, the risk extends beyond email accounts: many users reuse passwords across banking, social media, and other services, making credential stuffing attacks a serious secondary concern.

Implications for Japan's ISP Sector

The incident highlights a structural risk in Japan's ISP ecosystem: the consolidation of email infrastructure under a handful of large carriers means that a single breach can expose customers across dozens of consumer brands. While KDDI's rapid response limited the window of exposure, the scale of the breach raises questions about whether shared platforms should carry stronger isolation between ISP tenants.

Japan's Personal Information Protection Commission, which now has mandatory breach notification requirements, will likely scrutinize the third-party software vulnerability at the center of the attack. KDDI has disclosed the breach publicly, as reported by BleepingComputer and The Japan Times, and is cooperating with Japanese regulators. Affected users should change passwords immediately and enable two-factor authentication wherever available.

Originally reported by BleepingComputer. Read the original article for additional details.

View original source
Share: