Thecyberexpress KDDI Data Breach Exposes 14.22 Million Email Accounts
Article Content
- •KDDI's breach potentially exposes 14.22 million email accounts and passwords.
- •Attackers exploited a vulnerability in third-party software used in KDDI's email system.
- •KDDI has implemented security measures and is notifying affected users to change passwords.
KDDI, a Japanese telecommunications company, reported a significant data breach affecting up to 14.22 million email accounts. The breach was detected on June 17, 2026, when unauthorized access to an email system used by KDDI and several ISPs was identified. Attackers exploited a vulnerability in third-party software integrated into the email service. The compromised data includes email addresses and passwords, some of which were stored in hashed or encrypted formats. KDDI has taken immediate action to secure the system and is working with affected ISPs to notify users and encourage password changes. The company is also cooperating with regulatory authorities, including Japan's Personal Information Protection Commission. The breach raises concerns about the security of shared infrastructure among ISPs in Japan.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (12)
Following this threat?
Track KDDI in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…