KDDI Data Breach Exposes 14.22 Million Email Accounts

KDDI Data Breach Exposes 14.22 Million Email Accounts

First seen 24 Jun 2026, 08:45 UTC TheregisterThecyberexpressInfosecurity-MagazineTechnaduBleepingcomputer+5 91% similarity 69.0

Article Content

Browse articles
ThreatCluster

KDDI, a Japanese telecommunications company, reported a significant data breach affecting up to 14.22 million email accounts. The breach was detected on June 17, 2026, when unauthorized access to an email system used by KDDI and several ISPs was identified. Attackers exploited a vulnerability in third-party software integrated into the email service. The compromised data includes email addresses and passwords, some of which were stored in hashed or encrypted formats. KDDI has taken immediate action to secure the system and is working with affected ISPs to notify users and encourage password changes. The company is also cooperating with regulatory authorities, including Japan's Personal Information Protection Commission. The breach raises concerns about the security of shared infrastructure among ISPs in Japan.

Key Points: • KDDI's breach potentially exposes 14.22 million email accounts and passwords. • Attackers exploited a vulnerability in third-party software used in KDDI's email system. • KDDI has implemented security measures and is notifying affected users to change passwords.

ThreatCluster AI How this analysis works

Timeline

2026-06-17
Unauthorized access detected
KDDI identified unauthorized access to its email system, affecting multiple ISPs.
Thecyberexpress
2026-06-23
Public disclosure of the breach
KDDI publicly confirmed the data breach and the potential exposure of 14.22 million email accounts.
Infosecurity-Magazine
2026-06-24
KDDI issues warnings to users
KDDI urged users to change their passwords and informed relevant authorities about the breach.
Technadu

Community

Browse all →