01Summary
On 17 June 2026 KDDI detected unauthorised access to its ISP-facing email system. Attackers exploited a vulnerability in third-party software used on the platform. The system underpinned email services for KDDI and five other major Japanese ISPs. Up to 14.22 million email address and password combinations may have been exposed (including current, former and inactive accounts). Some passwords were stored in hashed or encrypted form. KDDI blocked the access the same day, patched the system, and notified the affected ISPs and Japanese regulators.
02Background
KDDI operates a shared/OEM email platform used by multiple Japanese ISPs. A single vulnerability in the underlying third-party software exposed credentials across six providers.
03Key revelations
- 01Single third-party software flaw on a shared ISP email platform exposed credentials for six major providers.
- 02Highlighted systemic risk of concentrated email infrastructure among Japanese ISPs.
04Technical analysis
Exploitation of an unnamed third-party software vulnerability on the shared email backend. No further technical details (malware, specific CVE, or threat actor) have been publicly released.
- Attack vector
- Exploitation of third-party software vulnerability
- Attack method
- Unauthorised access and credential extraction
- Initial access
- Exploitation of Public-Facing Application / Third-party software
- Exfiltration
- Direct access to credential store
Vulnerabilities exploited
- Unnamed third-party software vulnerability
05Threat actor
No public attribution.
06Victims and impact
Additional victims
- STNet
- JCOM
- Chubu Telecommunications
- NIFTY
- BIGLOBE
- KDDI Web Communications
Countries affected
- Japan
07Data exposed
Data types
- Email addresses
- Passwords (some hashed/encrypted)
08Financial damage
Credential reset campaigns across multiple ISPs; potential account takeover risk for users who re-used passwords.
09Timeline
- 2026-06-17Unauthorised access detected and blocked; system remediated.
- 2026-06-23Public disclosure by KDDI.
10Reaction and fallout
Public reaction
Calls for password resets and increased scrutiny of third-party software in critical telecom infrastructure.
11Legal
Notifications to Japan’s Personal Information Protection Commission and Ministry of Internal Affairs and Communications.
12Aftermath
Security improvements
- Immediate system patching and access blocking
- Notification and coordination with affected ISPs
13Significance and legacy
Significance
One of the largest pure credential exposures of 2026 in Japan, demonstrating the cascading risk of shared third-party platforms in the telecommunications sector.
14Disclosure and media
Publishing organisations
- BleepingComputer
- Nikkei
- The Japan News
- TechRadar
15Field notes
- 01The same backend powered email for six separate Japanese ISPs.
- 02Maximum claimed exposure was 14.22 million email/password pairs.
16Resolution
Access blocked and system remediated on the day of discovery (17 June 2026). Affected ISPs notified and password reset guidance issued.
17Sources
Official documents
- KDDI official press release (23 June 2026)
References
- [1]KDDI official statement
- [2]BleepingComputer
- [3]Nikkei
- [4]The Japan News









