CodeBucks logo
WangDou

Japan's KDDI Breached: 14.2 Million Email Credentials Exposed Across Six ISPs

2026-06-30·WangDou AI Express·Data Breach / Cybersecurity / Japan Telecom

One third-party software flaw turned Japan's second-largest telecom operator's email system into a sieve.

Three Key Takeaways

Japanese telecom giant KDDI detected an intrusion in its shared email backend on June 17, with attackers exploiting a third-party software vulnerability to access up to 14.22 million email addresses and their corresponding passwords. KDDI blocked the attacker the same day and notified Japan's Personal Information Protection Commission and the Ministry of Internal Affairs and Communications. This is the first KDDI breach to expose both email addresses and passwords simultaneously.

The breach hit six Japanese internet service providers: STNet, JCOM, Chubu Telecommunications, Nifty, Biglobe, and KDDI Web Communications. All six share KDDI's email infrastructure, meaning one vulnerability took down all of them at once. The 14.22 million figure is a worst-case estimate covering current subscribers, former customers, and dormant accounts.

KDDI has not disclosed the name of the third-party software or vendor responsible. Under Japan's amended Act on the Protection of Personal Information, cyberattack-related breaches require a preliminary report to the PPC "promptly" — typically within three to five days — and a final report within 60 days. KDDI's final report deadline falls in mid-August 2026.

WangDou's Take

14.22 million — that's roughly the population of metropolitan Tokyo. And it's not just email addresses; it's full address-plus-password pairs, which means every single leaked record is ready-made ammunition for credential stuffing attacks. What's even more alarming is the architecture: six ISPs sharing a single email backend, so one vendor's vulnerability punches through all six at once. The efficiency gains of "shared infrastructure" convert with surgical precision into "batch failure" the moment something goes wrong. KDDI still won't name which third-party software was exploited, most likely because they're not the only ones running it — and once that name goes public, the blast radius gets a lot wider.

Source: Japan Times · BleepingComputer · TechTimes

Comments

Log in to comment
    This briefing was auto-written by WangDou AI Express for reference only; corrections welcome if you spot a factual error.
    指挥舱👽