Cyber Incident Victim: KDDI
Timeline
Summary
KDDI detected unauthorized access to its shared email system, exploiting a zero‑day vulnerability in third‑party software used by five ISPs, and subsequently reported that up to 14.2 million email addresses and passwords may have been exposed, affecting current, former and inactive customers of those providers. The company evicted the attackers, implemented technical countermeasures, notified Japanese regulators, and began coordinating password resets and a patch for the vulnerable software while confirming that its mobile and fixed‑line email services remained unaffected.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On June 17, 2026, KDDI detected unauthorized access to its email system that is shared with five Japanese internet service providers: STNet, JCOM, Chubu Telecommunications, NIFTY, and BIGLOBE. The breach resulted from the exploitation of a zero‑day vulnerability in a third‑party software component that forms part of the email infrastructure developed by KDDI. KDDI’s mobile and fixed‑line internet email services, which operate on separate infrastructure, were not affected by the intrusion. Upon discovery, KDDI blocked the attacker and implemented technical countermeasures to prevent further unauthorized access. The same day, KDDI began notifying the affected ISPs and Japanese regulatory authorities, including the Personal Information Protection Commission and the Ministry of Internal Affairs and Communications.

The compromised data included email addresses and passwords, with KDDI confirming that the email addresses of approximately 12.2 million individuals and the passwords of about 7.6 million individuals were accessed. Other sources indicated that up to 14.2 million email addresses and passwords may have been exposed, affecting current, former, and inactive customers of the involved ISPs. KDDI stated that some of the passwords were stored in hashed or encrypted form, but the specific encryption methods and the proportion of plaintext versus protected credentials were not disclosed. There was no evidence of lateral movement, privilege escalation, or data exfiltration beyond the email system, and no malware, exploit kits, or specific tools were identified in the attack. The incident did not involve phishing, credential stuffing, or malware deployment as the initial access vector.
After evicting the hackers from its systems, KDDI worked with the affected ISPs to prompt password resets for the compromised accounts and announced that a mandatory password reset would be completed for all affected email accounts within the following days. The company also stated that it would thoroughly inspect the implicated software to ensure it did not contain additional vulnerabilities and would collaborate with the ISPs to transition to more secure communication technologies. KDDI reported the breach to Japan’s Personal Information Protection Commission and the Ministry of Internal Affairs and Communications as required by regulatory frameworks, and the investigation into the full scope and technical details remained ongoing. As of the latest public disclosures, no technical indicators of compromise, threat actor attribution, or details about the exploited vulnerability had been released. The breach prompted public disclosure and media coverage between June 23 and June 28, 2026.
