KDDI Data Breach May Expose 14.2 Million Email Accounts  | eSecurity Planet

KDDI Data Breach May Expose 14.2 Million Email Accounts 

KDDI disclosed a breach that may have exposed up to 14.2 million email accounts after attackers exploited a third-party software vulnerability.

Written By
Ken Underhill
Ken Underhill
Jun 29, 2026
2 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Japanese telecommunications operator KDDI Corporation has disclosed a data breach that may have exposed email addresses and passwords for up to 14.2 million customer accounts across six internet service providers (ISPs). 

The company discovered unauthorized access to a shared email system on June 17, blocked the attacker, and implemented additional defensive measures. 

Key Takeaways of the KDDI Incident

  • KDDI disclosed a breach that may have exposed the email addresses and passwords of up to 14.2 million accounts across six Japanese internet service providers.
  • Attackers exploited a vulnerability in third-party software, highlighting the downstream risks of shared infrastructure and supplier dependencies.
  • The exact impact remains under investigation, and KDDI has not disclosed how passwords were stored for all affected accounts, leaving the overall credential risk uncertain.
  • Exposed email credentials can enable spearphishing, credential stuffing, and account takeover attacks, even if some passwords were hashed or encrypted. 

Breach Affects Multiple Japanese ISPs

This incident impacted email services operated by KDDI as well as STNet, JCOM, Chubu Telecommunications, NIFTY, and BIGLOBE. 

KDDI is one of Japan’s largest telecommunications companies, with approximately 45,000 employees. 

The company estimated that up to 14.2 million accounts may have been exposed, including current customers, former customers, and inactive accounts that may no longer be in use.

KDDI said the investigation remains ongoing, and the exact number of affected accounts has not yet been confirmed. 

Because the impacted system supported multiple ISP operators, the breach shows how a shared service or supplier-dependent infrastructure can increase downstream risk when a single system is compromised.

Advertisement

Password Exposure Risk Remains Unclear

KDDI said some passwords were stored in hashed or encrypted form, which may reduce the likelihood of immediate account takeover. 

However, the company did not disclose the hashing or encryption methods used, whether salts were applied, or what percentage of accounts received stronger protection. 

Because password exposure risk depends heavily on how credentials are stored, weak hashing, reversible encryption, or plaintext storage could leave some users more vulnerable than others. 

Even if some passwords cannot be immediately abused, exposed email addresses and login data can still create risks for spearphishing, credential stuffing, and account takeover attempts. 

KDDI Notifies Regulators and Affected Providers

KDDI said it began contacting affected ISPs and reported the incident to Japan’s Personal Information Protection Commission and the Ministry of Internal Affairs and Communications. 

The company is also working with affected providers to implement additional security measures and reduce the risk to customers.

Impacted customers should reset their email passwords, enable two-factor authentication (2FA) where available, and use password managers

Organizations should monitor for unusual login activity, failed authentication spikes, suspicious forwarding rules, and phishing attempts targeting affected users. 

The KDDI breach highlights how third-party software vulnerabilities can create large-scale exposure when they affect centralized infrastructure. 

Zero trust solutions can help organizations limit the impact of compromised credentials and third-party risk through continuous verification and least-privilege access. 

Ken Underhill

Ken Underhill is an award-winning cybersecurity professional, bestselling author, and seasoned IT professional. He holds a graduate degree in cybersecurity and information assurance from Western Governors University and brings years of hands-on experience to the field.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.