KDDI Corporation has disclosed a data breach that may have exposed the email account credentials of up to 14.2 million users after attackers exploited a vulnerability in third-party software used within the company’s email infrastructure.
The Japanese telecommunications provider said it detected suspicious activity on June 17, 2026, and immediately blocked the unauthorized access while implementing additional security measures. An internal investigation determined that the attackers gained access by exploiting a vulnerability in an unnamed third-party software product deployed on one of KDDI’s email systems.
Multiple ISPs affected
According to KDDI, the compromised system provides email services for five internet service providers in Japan:
- STNet, Inc.
- JCOM Co., Ltd.
- Chubu Telecommunications Co., Inc.
- NIFTY Corporation
- BIGLOBE Inc.
The company estimates that email addresses and passwords belonging to as many as 14.2 million current, former, and inactive customer accounts may have been exposed. KDDI noted that the investigation remains ongoing and the final number of affected accounts has not yet been confirmed.
Password protection varies
KDDI said some passwords were stored in hashed or encrypted form, which could reduce the risk of immediate credential abuse if the data were accessed. However, the company did not disclose what percentage of passwords were protected, what hashing or encryption methods were used, or whether any credentials were stored in plaintext.
Because of that uncertainty, affected users are being advised to change their email passwords as soon as possible and enable multi-factor authentication where available.
Authorities notified
KDDI said it began notifying the affected internet service providers on June 17 after identifying the breach. The company also reported the incident to Japan’s Personal Information Protection Commission and the Ministry of Internal Affairs and Communications.
According to KDDI, it is continuing to work with the impacted ISPs to strengthen security controls and reduce the risk of further unauthorized access while the investigation remains ongoing.
The incident serves as another reminder that vulnerabilities in third-party software can create widespread downstream impacts, particularly when service providers host infrastructure used by multiple organizations and millions of customers.
BreachNews will report on any additional findings if KDDI releases further details about the incident or confirms the final number of affected accounts.












