KDDI email breach exposes 14 million accounts
Attackers exploited a flaw in third-party software used by KDDI's shared email platform. The breach exposed 12,231,954 email addresses and 7,616,173 passwords across KDDI and five partner ISPs. A KDDI subsidiary, KDDI Web Communications, separately confirmed on August 24 that 1,250,543 mail accounts on its CPI hosting brand were also hit through the same platform flaw. Two Japanese government bodies have taken action: the communications ministry ordered fixes and harm reports on July 29, and on August 19 the Personal Information Protection Commission issued its own administrative guidance, saying KDDI's security measures were insufficient, and ordered a report on recurrence prevention by October 19.
- Started
- Jun 23, 2026
- Latest activity
- Aug 24, 2026
- Attributed to
- Not confirmedNo credible attribution yet
- Where
- Japan
- Sectors
- Telecom, Consumers
- Scale
- KDDI and five Japanese internet providers, with 12,231,954 email addresses and 7,616,173 passwords confirmed exposed.
Current status
On August 24, 2026, KDDI Web Communications said its investigation was complete and no newer public update has been found.
Contained: The attack has been stopped or blocked. Recovery and investigation are still running.
Impact
Attackers accessed the shared email system and exposed 12,231,954 email addresses and 7,616,173 passwords. Japan's communications ministry said the stolen passwords left about 7.62 million users' mailbox contents open to viewing. On August 19, Japan's privacy regulator separately found KDDI's security measures were insufficient and ordered a written report on how it will prevent a repeat, due October 19. KDDI Web Communications, a KDDI subsidiary running the CPI hosting brand, said on August 24 that its own review of 1,250,543 exposed mail accounts on that platform is complete and customer notifications finished in July. Neither notice has said whether anyone actually viewed the exposed mailboxes.
What to do
Affected users should change their email account password now and turn on two-factor authentication if the ISP or hosting provider offers it.
Timeline
-
Aug 24, 2026
KDDI Web Communications, a KDDI subsidiary operating the CPI rental server and business hosting brand, said its investigation is complete: 1,250,543 CPI mail accounts were exposed through the same platform flaw. It said affected customers were individually notified by email between July 7 and July 9.
Containedscan.netsecurity.ne.jp -
Aug 19, 2026
Japan's Personal Information Protection Commission issued administrative guidance to KDDI, separate from the communications ministry's July 29 order, saying KDDI's security measures were insufficient and ordering a report on recurrence prevention steps by October 19, 2026.
Containednikkei.com -
Aug 7, 2026
At KDDI's quarterly earnings briefing, president Hiromichi Matsuda said the company is treating the communications ministry's administrative guidance seriously and is fast tracking a vulnerability review across all of its systems, not just the breached mail platform, aiming to finish by the end of September or by the end of the year.
Containedreaitimenews.com -
Jul 29, 2026
Japan's communications ministry issued administrative guidance to KDDI after finding that stolen passwords left about 7.62 million users' mailbox contents open to viewing. It ordered KDDI to report on its fixes and any follow-on harm by August 31, followed by quarterly reports for at least one year.
Containedsoumu.go.jp -
Jul 21, 2026
KDDI corrected the confirmed number of people whose email addresses were exposed to 12,231,954. The confirmed password count remained 7,616,173, and KDDI did not announce a full closeout.
Containednewsroom.kddi.com -
Jul 8, 2026
KDDI said the confirmed affected count stood at over 12 million people and urged password changes.
Containedbleepingcomputer.com -
Jun 28, 2026
Reports confirmed the breach could expose up to 14.2 million email logins across the six ISPs.
Activebleepingcomputer.com -
Jun 23, 2026
KDDI publicly disclosed that attackers had gained unauthorized access to an email platform it operates for itself and five other Japanese ISPs.
Emerginginfosecurity-magazine.com
Sources
- Japanese telecom giant KDDI says data breach affects 12 million people BleepingComputer Jul 8, 2026
- KDDI Breach Affects Six Japanese ISPs, Exposes 14.2 Million Email Credentials Infosecurity Magazine Jun 24, 2026
- Japanese Telecom Giant Says Breach May Expose 14.2 Million Email Accounts TechRepublic Jun 29, 2026
- KDDI Data Breach: Millions of Emails and Passwords Compromised SecurityOnline Jul 9, 2026
- Apology and report on unauthorized access to the email system for ISP providers KDDI Jul 21, 2026
- Administrative guidance to KDDI on protecting the secrecy of communications Japan Ministry of Internal Affairs and Communications Jul 29, 2026
- Japan's communications ministry issues administrative guidance to KDDI over ISP email breach INTERNET Watch Jul 30, 2026
- KDDI, full-system vulnerability review targeted for end of September Real-Time News Navi Aug 8, 2026
- KDDI profit up 22% on strong mobile and data center business, breach scandal casts a shadow Nikkei Aug 7, 2026
- Unauthorized access to KDDI's ISP-facing email system, ministry issues administrative guidance ScanNetSecurity Aug 10, 2026
- KDDI breach exploited a zero-day vulnerability, company to use AI in future defenses ZDNET Japan Jul 6, 2026
- Personal Information Protection Commission gives KDDI administrative guidance over mail data leak Nikkei Aug 19, 2026
- Privacy watchdog gives KDDI administrative guidance over leak of 12.23 million people's data MSN Japan (Jiji) Aug 19, 2026
- KDDIのISP事業者向けメールシステムへの不正アクセス、レンタルサーバCPIへの影響が明らかに ScanNetSecurity Aug 31, 2026 unverified
Related reports
- KDDI data breach exposes 12 million users' info Jul 9, 2026
- KDDI email and password leak Jul 9, 2026
- Oracle has a security flaw Jul 9, 2026
- KDDI breach leaks 14.2 million email passwords Jun 24, 2026