EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/2026-kddi-isp-email-breach
026/430

File EL-0405HighResolvedData Breach / Credential Exposure / Third-Party Software Exploitation

KDDI ISP Email Platform Data Breach

Also filed as KDDI Email System Breach · Japanese ISP Credential Leak 2026

Unauthorised access to a shared email platform operated by KDDI for multiple Japanese internet service providers, resulting in the potential exposure of millions of email addresses and passwords.

  • #telecommunications
  • #credentials
  • #email-passwords
  • #japan
  • #third-party-software
  • #isp
Notoriety8/10
Event
17 Jun 2026
Disclosed
23 Jun 2026
Target
KDDI
Scale
14.2M people
Status
Resolved

01Summary

On 17 June 2026 KDDI detected unauthorised access to its ISP-facing email system. Attackers exploited a vulnerability in third-party software used on the platform. The system underpinned email services for KDDI and five other major Japanese ISPs. Up to 14.22 million email address and password combinations may have been exposed (including current, former and inactive accounts). Some passwords were stored in hashed or encrypted form. KDDI blocked the access the same day, patched the system, and notified the affected ISPs and Japanese regulators.

02Background

KDDI operates a shared/OEM email platform used by multiple Japanese ISPs. A single vulnerability in the underlying third-party software exposed credentials across six providers.

03Key revelations

  1. 01Single third-party software flaw on a shared ISP email platform exposed credentials for six major providers.
  2. 02Highlighted systemic risk of concentrated email infrastructure among Japanese ISPs.

04Technical analysis

Exploitation of an unnamed third-party software vulnerability on the shared email backend. No further technical details (malware, specific CVE, or threat actor) have been publicly released.

Attack vector
Exploitation of third-party software vulnerability
Attack method
Unauthorised access and credential extraction
Initial access
Exploitation of Public-Facing Application / Third-party software
Exfiltration
Direct access to credential store

Vulnerabilities exploited

  • Unnamed third-party software vulnerability

05Threat actor

No public attribution.

06Victims and impact

Additional victims

  • STNet
  • JCOM
  • Chubu Telecommunications
  • NIFTY
  • BIGLOBE
  • KDDI Web Communications

Countries affected

  • Japan

07Data exposed

Data types

  • Email addresses
  • Passwords (some hashed/encrypted)

08Financial damage

Credential reset campaigns across multiple ISPs; potential account takeover risk for users who re-used passwords.

09Timeline

  1. 2026-06-17Unauthorised access detected and blocked; system remediated.
  2. 2026-06-23Public disclosure by KDDI.

10Reaction and fallout

Public reaction

Calls for password resets and increased scrutiny of third-party software in critical telecom infrastructure.

11Legal

Notifications to Japan’s Personal Information Protection Commission and Ministry of Internal Affairs and Communications.

12Aftermath

Security improvements

  • Immediate system patching and access blocking
  • Notification and coordination with affected ISPs

13Significance and legacy

Significance

One of the largest pure credential exposures of 2026 in Japan, demonstrating the cascading risk of shared third-party platforms in the telecommunications sector.

14Disclosure and media

Publishing organisations

  • BleepingComputer
  • Nikkei
  • The Japan News
  • TechRadar

15Field notes

  1. 01The same backend powered email for six separate Japanese ISPs.
  2. 02Maximum claimed exposure was 14.22 million email/password pairs.

16Resolution

Access blocked and system remediated on the day of discovery (17 June 2026). Affected ISPs notified and password reset guidance issued.

17Sources

Official documents

  • KDDI official press release (23 June 2026)

References

  1. [1]KDDI official statement
  2. [2]BleepingComputer
  3. [3]Nikkei
  4. [4]The Japan News
Fact sheetEL-0405

Dates

Event
17 Jun 2026
Ended
17 Jun 2026
Discovered
17 Jun 2026
Disclosed
23 Jun 2026
Resolved
17 Jun 2026
Ongoing
No

Target

Organisation
KDDI Corporation
Type
Telecommunications Company
Sector
Telecommunications
Country
Japan

Actor

Motivation
Unknown (likely credential harvesting / resale)
Arrested
No
Convicted
No

Data

People
14,220,000
Records
14,220,000
Sensitivity
High
Published
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.