SHINDO5

KDDI CORPORATION

Email addresses12.2Mpeople

POSSIBLE LEAKPasswordUnauthorized access · Investigating

Open in the live monitor ▶
Disclosed
Jun 25, 2026
Detected
Jun 17, 2026
Detection to disclosure
8 days
Leak
Leak possible
Type
Unauthorized access
Status
Investigating
Security spend
Not checked yet
Compensation
Not announced

What leaked

ContactEmail address
CredentialsPassword

How many

  • Email addresses 12.2M people
  • Of which passwords were included 7.6M people
  • Maximum count at first report (email addresses and passwords) up to 14.2M records

Who is affected

  • Users of ISPs' email services
  • ISPs using the system

Cause

A vulnerability (zero-day) in third-party software was exploited

Timeline

  1. Attacks from May 16 onward (Security NEXT)
  2. Vulnerability identified (Security NEXT)
  3. Date of Cybersecurity-jp.com's first article
  4. Disclosed exploitation of a zero-day vulnerability, among other details
  5. The PPC took administrative action against KDDI and the ISPs

Response

  • Forensic investigation

KDDI investigated the scope and period of impact

What you should do

  1. Change this password and every account that reused it now. Switch to a passkey where offered
  2. Don't open links in emails from this company. The apology email itself may be fake
  3. Check the company's notice to see if you're affected

Lessons for companies

  1. Inventory internal tools (BI, CMS) as exposed assets. 'Internal only' is not a defense
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources