Contained High impact Data breach Checked 16h ago

KDDI email breach exposes 14 million accounts

Attackers exploited a flaw in third-party software used by KDDI's shared email platform. The breach exposed 12,231,954 email addresses and 7,616,173 passwords across KDDI and five partner ISPs. A KDDI subsidiary, KDDI Web Communications, separately confirmed on August 24 that 1,250,543 mail accounts on its CPI hosting brand were also hit through the same platform flaw. Two Japanese government bodies have taken action: the communications ministry ordered fixes and harm reports on July 29, and on August 19 the Personal Information Protection Commission issued its own administrative guidance, saying KDDI's security measures were insufficient, and ordered a report on recurrence prevention by October 19.

Started
Jun 23, 2026
Latest activity
Aug 24, 2026
Attributed to
Not confirmedNo credible attribution yet
Where
Japan
Sectors
Telecom, Consumers
Scale
KDDI and five Japanese internet providers, with 12,231,954 email addresses and 7,616,173 passwords confirmed exposed.

Current status

On August 24, 2026, KDDI Web Communications said its investigation was complete and no newer public update has been found.

Contained: The attack has been stopped or blocked. Recovery and investigation are still running.

Impact

Attackers accessed the shared email system and exposed 12,231,954 email addresses and 7,616,173 passwords. Japan's communications ministry said the stolen passwords left about 7.62 million users' mailbox contents open to viewing. On August 19, Japan's privacy regulator separately found KDDI's security measures were insufficient and ordered a written report on how it will prevent a repeat, due October 19. KDDI Web Communications, a KDDI subsidiary running the CPI hosting brand, said on August 24 that its own review of 1,250,543 exposed mail accounts on that platform is complete and customer notifications finished in July. Neither notice has said whether anyone actually viewed the exposed mailboxes.

What to do

Affected users should change their email account password now and turn on two-factor authentication if the ISP or hosting provider offers it.

Timeline

  1. Aug 24, 2026

    KDDI Web Communications, a KDDI subsidiary operating the CPI rental server and business hosting brand, said its investigation is complete: 1,250,543 CPI mail accounts were exposed through the same platform flaw. It said affected customers were individually notified by email between July 7 and July 9.

    Containedscan.netsecurity.ne.jp
  2. Aug 19, 2026

    Japan's Personal Information Protection Commission issued administrative guidance to KDDI, separate from the communications ministry's July 29 order, saying KDDI's security measures were insufficient and ordering a report on recurrence prevention steps by October 19, 2026.

    Containednikkei.com
  3. Aug 7, 2026

    At KDDI's quarterly earnings briefing, president Hiromichi Matsuda said the company is treating the communications ministry's administrative guidance seriously and is fast tracking a vulnerability review across all of its systems, not just the breached mail platform, aiming to finish by the end of September or by the end of the year.

    Containedreaitimenews.com
  4. Jul 29, 2026

    Japan's communications ministry issued administrative guidance to KDDI after finding that stolen passwords left about 7.62 million users' mailbox contents open to viewing. It ordered KDDI to report on its fixes and any follow-on harm by August 31, followed by quarterly reports for at least one year.

    Containedsoumu.go.jp
  5. Jul 21, 2026

    KDDI corrected the confirmed number of people whose email addresses were exposed to 12,231,954. The confirmed password count remained 7,616,173, and KDDI did not announce a full closeout.

    Containednewsroom.kddi.com
  6. Jul 8, 2026

    KDDI said the confirmed affected count stood at over 12 million people and urged password changes.

    Containedbleepingcomputer.com
  7. Jun 28, 2026

    Reports confirmed the breach could expose up to 14.2 million email logins across the six ISPs.

    Activebleepingcomputer.com
  8. Jun 23, 2026

    KDDI publicly disclosed that attackers had gained unauthorized access to an email platform it operates for itself and five other Japanese ISPs.

    Emerginginfosecurity-magazine.com

Sources

Related reports