Morning Overview

A breach at Japan’s KDDI exposed 12 million email addresses and 7.6 million passwords

KDDI, one of Japan’s largest telecommunications companies, has confirmed a data breach that exposed roughly 12 million email addresses and about 7.6 million passwords tied to email services it operates for several major Japanese internet providers. The company said attackers exploited a previously unknown vulnerability in third-party software to reach the affected system, and it has warned users that their credentials may be at risk even though passwords were stored in protected form. The incident stands as one of the larger telecommunications data breaches disclosed in the country in recent memory.

The compromised platform underpinned email accounts across a group of internet service providers that rely on KDDI’s infrastructure. Because a single shared system served customers of multiple providers, the breach reached across brands, sweeping in subscribers who may not have realized their email was administered by KDDI. The company responded by patching the flaw, adding technical defenses and forcing password resets for affected accounts.

The scale of the exposed credentials

KDDI reported that the breach confirmed the exposure of approximately 12.23 million email addresses and around 7.61 million passwords, with the potential compromise of a larger pool of up to roughly 14.22 million sets of credentials. Email addresses and passwords are a particularly sensitive pairing, because they can be used to attempt account takeovers not only on the breached service but on other sites where people reuse the same combination. Even where passwords were hashed or encrypted, the company cautioned that they could still be vulnerable to cracking or misuse, which is why it pushed users to reset them. Coverage from The Japan Times detailed the figures the company confirmed.

A zero-day flaw in third-party software

According to KDDI, the attackers gained access by exploiting a zero-day vulnerability, meaning a security flaw that was unknown to the software’s vendor and had no available fix at the time of the attack. The company indicated that the vulnerability sat in third-party software used by its email platform, and that the flaw had not yet been recognized by the vendor when the intrusion was confirmed. Zero-day exploits are especially dangerous because defenders cannot patch a hole they do not know exists, giving attackers a window to operate before the problem is identified and closed.

How long the intruders had access

The timeline KDDI described points to an extended period of unauthorized access. The company said the attackers breached the platform in mid-May 2026, while the intrusion was not confirmed until mid-June 2026, leaving roughly a month during which the attackers could operate inside the system before detection. A gap of that length between initial compromise and discovery is a common feature of major breaches and can significantly increase the amount of data an attacker is able to reach or remove. An analysis of the incident noted the extended dwell time before the breach was caught.

The internet providers caught up in the breach

The affected email services were tied to a set of internet service providers that use KDDI’s platform, including operators such as STNet, JCOM, Chubu Telecommunications, NIFTY and BIGLOBE. Consolidating email for multiple providers on shared infrastructure is efficient, but it also concentrates risk, so that a single successful attack can affect the customers of every brand relying on that system, as reporting on the breach noted in describing the range of services caught up in the incident. For subscribers, the practical result is that an account they associate with one provider may have been exposed through a breach at a different company entirely.

What KDDI did in response

Once the intrusion was confirmed, KDDI moved to close the vulnerability and strengthen its defenses. The company patched the flaw that had been exploited, implemented additional technical protective measures and enforced password resets for the accounts it identified as affected. Forcing a password reset is a standard containment step after credential exposure, because it invalidates the stolen passwords for the breached service, though it does nothing to protect other sites where a person may have reused the same password. That is why security guidance consistently urges people to use unique passwords for each account.

The risks for affected users

For the millions of people whose information was exposed, the most immediate danger is credential stuffing, in which attackers take stolen email-and-password combinations and try them automatically across many other online services. Exposed email addresses also fuel targeted phishing, giving scammers a verified list of addresses and, potentially, context that makes fraudulent messages more convincing. Security specialists generally advise anyone caught in such a breach to change reused passwords, enable multi-factor authentication where available, and treat unexpected messages referencing their accounts with caution.

A reminder of infrastructure risk

The KDDI breach illustrates how much sensitive data can be concentrated in the shared systems that power everyday services like email, and how a flaw in a single piece of third-party software can cascade into the exposure of millions of accounts. It also underscores the difficulty of defending against zero-day vulnerabilities, which can undermine even well-resourced organizations before anyone knows a fix is needed. As telecommunications and internet providers continue to consolidate services onto common platforms, the potential blast radius of any one successful attack grows, keeping the security of that underlying infrastructure a central concern for both companies and the customers who depend on them.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview