KDDI says attackers broke into an email service it runs for itself and other Japanese internet providers, potentially exposing data tied to up to 14.2 million users. The company said it detected unauthorized access on June 17 and believes the attackers exploited a vulnerability in third-party software used by the platform. KDDI says affected data may include email addresses, hashed and encrypted passwords, and some personal information, including for dormant or canceled accounts. Customers of STNet, JCOM, Chubu Telecommunications, Nifty, and BIGLOBE may also be affected.
Ionut Arghire
2026.07.09
97% relevant
This source updates the same KDDI managed email-platform breach, adding a refined impact figure of over 12 million affected people, saying the intrusion occurred on June 17, naming five impacted ISPs, and stating that attackers exploited a zero-day in third-party software for which a patch is still being developed.
Sergiu Gatlan
2026.07.08
98% relevant
This is the same KDDI managed email-platform breach and adds updated confirmed impact numbers, naming 12,233,087 exposed email addresses and 7,616,173 passwords, plus new detail that the intrusion began on May 16 via a third-party zero-day that was still unknown to the vendor as of June 17.
2026.07.07
97% relevant
This is the same KDDI managed-email-platform breach and adds finalized forensic findings: 12.2 million email addresses and 7.6 million passwords were exposed across five Japanese ISPs, with KDDI attributing the intrusion to exploitation of a third-party software vulnerability and saying affected providers are enforcing password resets.
SecurityWeek News
2026.07.03
96% relevant
This article repeats the key scope of the KDDI breach and names the five affected ISP operators, reinforcing that the incident likely exposed email addresses and passwords for roughly 14.22 million people.
2026.07.01
90% relevant
This is the same KDDI managed-email breach and adds that attackers exploited a vulnerability in third-party software, that KDDI says it blocked the intrusion quickly, and that the affected downstream providers include STNet, JCOM, Chubu Telecommunications, NIFTY, and BIGLOBE.
2026.06.24
100% relevant
This article appears to be the first tracked report of KDDI's disclosure that unauthorized access to its managed email platform may have exposed credentials and personal data for users across multiple Japanese ISPs.