Back to Blog
2026-06-24· 5 min read

KDDI Breach Exposes 14.2 Million Email Credentials Across Six Japanese ISPs

Japanese telecom giant KDDI confirmed a breach affecting six ISPs, exposing 14.22 million email addresses and passwords. Learn about the vulnerability and how to protect your accounts.

Data Breach Telecom Japan Email Security Credential Theft

What Happened


On June 23, 2026, KDDI Corporation — one of Japan's largest telecommunications operators — confirmed a data breach that affected its email system used by six internet service providers (ISPs). Up to **14.22 million email addresses and passwords** were potentially compromised.


Which ISPs Were Affected


The breach impacted customers of:


  • STNet Pikara Light, Pikara Mobile, Oshigoto Pikara services
  • KDDI Web Communications Rental server CPI email
  • JCOM J:COM NET and cable TV operators
  • Chubu Telecommunications COMINA Hikari and Business COMINA
  • Nifty Corporation @nifty email
  • Biglobe BIGLOBE email

  • How the Attack Happened


    KDDI detected the intrusion on **June 17, 2026**. The company confirmed that the attacker exploited a **vulnerability in third-party software** used in the email system.


    This highlights a critical security risk: even when your own systems are secure, a vulnerability in a third-party tool can expose millions of users.


    What Data Was Exposed


    The compromised information includes:


  • Email addresses
  • Passwords
  • Account credentials for both active and inactive users

  • KDDI specifically noted that accounts of customers who had canceled services or hadn't used email for a long time were also affected.


    Immediate Actions for Affected Users


    1. Change Your Password Immediately

    If you use any of the affected email services, change your password right now — even if you don't actively use the account.


    2. Enable Two-Factor Authentication

    Enable 2FA on your email account and any other accounts that use the same password.


    3. Check for Suspicious Activity

    Review your email account for:

  • Unauthorized login attempts
  • Forwarding rules you didn't set up
  • Sent messages you didn't write

  • 4. Update Other Accounts

    If you reused the same password elsewhere, change those accounts too. Credential reuse is how one breach becomes many.


    Lessons for Organizations


    Third-Party Risk Management

  • Audit all third-party software dependencies
  • Monitor for vulnerabilities in connected systems
  • Implement network segmentation to limit blast radius

  • Credential Security

  • Enforce password complexity requirements
  • Implement credential rotation policies
  • Deploy breach detection tools that monitor for leaked credentials

  • Check Your Domain Security


    Use Vaarta.space to scan your domain for security misconfigurations that could expose you to similar attacks.


    [Free domain security scan](https://vaarta.space)


    Ready to check your domain security?

    Run a free scan to identify potential vulnerabilities.

    Start Free Scan