KDDI Corporation
Incident posture
Linked entities
- Victim
- KDDI Corporation
- Threat actors
- 0 actors
- Sources
- 3 sources
Timeline
Summary
KDDI Corporation reported an unauthorized intrusion into its shared email platform affecting several Japanese ISPs, stemming from exploitation of a zero‑day flaw in third‑party software. The breach exposed email addresses and passwords for up to fourteen million accounts, including active, former and inactive users. Upon detection, the attacker was blocked, the compromised system was secured, and notifications were sent to regulators and partner ISPs. The company confirmed no further suspicious activity and is coordinating password resets while reviewing the software for additional vulnerabilities.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On June 17, 2026, KDDI Corporation detected unauthorized access to its email system that is shared with several Japanese internet service providers. The breach was traced to the exploitation of a zero‑day vulnerability in third‑party software integrated into the email infrastructure. According to KDDI’s notices, the attack compromised the email addresses of approximately 12.2 million individuals and the passwords of about 7.6 million users, while other sources indicate that up to 14.2 million email addresses and passwords may have been exposed across current, former and inactive accounts of the affected ISPs. The affected services include email offerings from STNet, JCOM, Chubu Telecommunications, NIFTY and BIGLOBE, with some reports also mentioning KDDI Web Communications as part of the shared platform. KDDI confirmed that its mobile and fixed‑line email services, which run on separate infrastructure, were not impacted by the intrusion.
Upon discovery, KDDI immediately blocked the attacker and applied technical countermeasures to prevent further unauthorized access. The company began notifying the affected ISPs and Japanese regulatory authorities, including the Personal Information Protection Commission and the Ministry of Internal Affairs and Communications, on the same day. KDDI stated that it worked with the ISPs to prompt password resets and that customers who regularly use their email accounts had already updated their login information, while a mandatory password reset for all affected email accounts was scheduled to be completed within the following days. In addition, KDDI indicated that it had evicted the hackers from its systems and found no evidence of additional suspicious activity after the containment actions. The company also said it would thoroughly inspect the implicated software for other vulnerabilities and collaborate with the ISPs to transition to more secure communication technologies.
KDDI’s public disclosures noted that some of the compromised passwords were stored in hashed or encrypted form, but the specific encryption methods and the proportion of accounts stored in plaintext versus protected formats were not disclosed. The investigation remained ongoing, with no technical indicators of compromise such as file hashes, malicious domains or IP addresses made public, and no threat actor attribution provided by KDDI, law enforcement or security firms. The company continued to coordinate mitigation efforts with the ISPs, including customer alerts and system‑level countermeasures, and urged users to follow the guidance issued by their respective providers. No evidence of malware deployment, phishing, credential stuffing, lateral movement, privilege escalation or data exfiltration beyond the email system was reported in the available sources.
Sources
Sources available to members: 3 sources.