KDDI Breach Exposes 14.2 Million Email Credentials Across Six Japanese ISPs
Japanese telecom giant KDDI confirmed a breach affecting six ISPs, exposing 14.22 million email addresses and passwords. Learn about the vulnerability and how to protect your accounts.
What Happened
On June 23, 2026, KDDI Corporation — one of Japan's largest telecommunications operators — confirmed a data breach that affected its email system used by six internet service providers (ISPs). Up to **14.22 million email addresses and passwords** were potentially compromised.
Which ISPs Were Affected
The breach impacted customers of:
How the Attack Happened
KDDI detected the intrusion on **June 17, 2026**. The company confirmed that the attacker exploited a **vulnerability in third-party software** used in the email system.
This highlights a critical security risk: even when your own systems are secure, a vulnerability in a third-party tool can expose millions of users.
What Data Was Exposed
The compromised information includes:
KDDI specifically noted that accounts of customers who had canceled services or hadn't used email for a long time were also affected.
Immediate Actions for Affected Users
1. Change Your Password Immediately
If you use any of the affected email services, change your password right now — even if you don't actively use the account.
2. Enable Two-Factor Authentication
Enable 2FA on your email account and any other accounts that use the same password.
3. Check for Suspicious Activity
Review your email account for:
4. Update Other Accounts
If you reused the same password elsewhere, change those accounts too. Credential reuse is how one breach becomes many.
Lessons for Organizations
Third-Party Risk Management
Credential Security
Check Your Domain Security
Use Vaarta.space to scan your domain for security misconfigurations that could expose you to similar attacks.
[Free domain security scan](https://vaarta.space)
Related Articles
FortiBleed: 430,000+ FortiGate Firewalls Compromised, 110 Million Credentials Stolen
A massive credential-harvesting campaign dubbed FortiBleed has silently compromised over 430,000 FortiGate firewalls globally, stealing 110 million+ credentials from live network traffic since February 2026.
2026-05-20How to Protect Against Phishing Attacks — SPF, DKIM, DMARC Guide | Vaarta
Learn how to protect against phishing attacks with email authentication. Configure SPF, DKIM, DMARC, and security headers to prevent domain spoofing.
2026-06-08AI-Powered Phishing Attacks in 2026 — How to Detect and Prevent Them
Learn how AI-generated phishing emails bypass traditional security. Discover detection techniques, real-world examples, and protection strategies against modern phishing.
Ready to check your domain security?
Run a free scan to identify potential vulnerabilities.
Start Free Scan