KDDI Says Third-Party Software Breach May Have Exposed 14.2 Million Email Accounts

KDDI disclosed a breach affecting email systems used by five Japanese ISPs, with up to 14.2 million email accounts potentially exposed.
KDDI corporate logo displayed over the exterior of a modern glass office building representing the Japanese telecommunications company.
KDDI disclosed a data breach after attackers exploited a vulnerability in third-party software, potentially exposing email account credentials belonging to up to 14.2 million customers across multiple Japanese internet service providers.

KDDI Corporation has disclosed a data breach that may have exposed the email account credentials of up to 14.2 million users after attackers exploited a vulnerability in third-party software used within the company’s email infrastructure.

The Japanese telecommunications provider said it detected suspicious activity on June 17, 2026, and immediately blocked the unauthorized access while implementing additional security measures. An internal investigation determined that the attackers gained access by exploiting a vulnerability in an unnamed third-party software product deployed on one of KDDI’s email systems.

Multiple ISPs affected

According to KDDI, the compromised system provides email services for five internet service providers in Japan:

  • STNet, Inc.
  • JCOM Co., Ltd.
  • Chubu Telecommunications Co., Inc.
  • NIFTY Corporation
  • BIGLOBE Inc.

The company estimates that email addresses and passwords belonging to as many as 14.2 million current, former, and inactive customer accounts may have been exposed. KDDI noted that the investigation remains ongoing and the final number of affected accounts has not yet been confirmed.

Password protection varies

KDDI said some passwords were stored in hashed or encrypted form, which could reduce the risk of immediate credential abuse if the data were accessed. However, the company did not disclose what percentage of passwords were protected, what hashing or encryption methods were used, or whether any credentials were stored in plaintext.

Because of that uncertainty, affected users are being advised to change their email passwords as soon as possible and enable multi-factor authentication where available.

Authorities notified

KDDI said it began notifying the affected internet service providers on June 17 after identifying the breach. The company also reported the incident to Japan’s Personal Information Protection Commission and the Ministry of Internal Affairs and Communications.

According to KDDI, it is continuing to work with the impacted ISPs to strengthen security controls and reduce the risk of further unauthorized access while the investigation remains ongoing.

The incident serves as another reminder that vulnerabilities in third-party software can create widespread downstream impacts, particularly when service providers host infrastructure used by multiple organizations and millions of customers.

BreachNews will report on any additional findings if KDDI releases further details about the incident or confirms the final number of affected accounts.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site
INTEL.BREACHNEWS.COM

Live Cyber
Threat Map

Explore live cyber activity, recent breach reports, KEV alerts, and public threat feeds from a single interactive dashboard.

Launch Threat Map