Thecyberexpress
KDDI Data Breach Exposes 14.22 Million Email Accounts
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
KDDI, a Japanese telecommunications company, reported a significant data breach affecting up to 14.22 million email accounts. The breach was detected on June 17, 2026, when unauthorized access to an email system used by KDDI and several ISPs was identified. Attackers exploited a vulnerability in third-party software integrated into the email service. The compromised data includes email addresses and passwords, some of which were stored in hashed or encrypted formats. KDDI has taken immediate action to secure the system and is working with affected ISPs to notify users and encourage password changes. The company is also cooperating with regulatory authorities, including Japan's Personal Information Protection Commission. The breach raises concerns about the security of shared infrastructure among ISPs in Japan.
Key Points: • KDDI's breach potentially exposes 14.22 million email accounts and passwords. • Attackers exploited a vulnerability in third-party software used in KDDI's email system. • KDDI has implemented security measures and is notifying affected users to change passwords.