breach
KDDI Breach: 12 Million Emails, 7.6 Million Passwords Exposed
2026-07-08

KDDI, one of Japan's three largest telcos, has finally attached numbers to the breach it disclosed in June. More than 12.2 million customer email addresses and 7.6 million passwords were exposed after attackers exploited a flaw in third-party software running its shared email platform.
The platform handles webmail, storage and account management for five Japanese internet service providers. KDDI's own consumer email service for mobile and broadband customers runs on separate infrastructure and was not caught up in the incident. The company says it patched the vulnerability as soon as the intrusion was spotted, and that investigators found no evidence the attackers moved beyond the initial foothold.
Password resets, with a hint
The affected ISPs are working through mandatory password resets. KDDI notes that many regular users of the email service have already changed their credentials, which is a polite way of saying anyone who recycles those passwords elsewhere should probably get on with it too. Credential reuse is the quiet accelerant that turns one breach into several, and 7.6 million exposed passwords is a lot of tinder.
A rough patch for corporate Japan
The disclosure lands in the middle of a bruising stretch for Japanese enterprises. Aflac's Japanese arm, motor manufacturer Nidec and brewer Sapporo Holdings have all reported cyber incidents or disruptions in recent weeks, with no known link between them.
Separately, Tokyo police arrested a 15-year-old accused of exploiting a vulnerability in Bandai Channel's servers to cancel more than 46,000 anime subscriptions. It is an unusually specific way to ruin thousands of Sundays, and a reminder that not every attacker is after money or data.
Third-party software, first-party problem
The through-line here is familiar. Third-party software remains the soft underbelly of large providers. Telcos and ISPs invest heavily in their own infrastructure, harden their own perimeters, drill their own staff, and then discover that the shared platform sitting quietly in the background has a flaw someone else found first.
When that platform gets popped, the customers wear the consequences regardless of how tidy the first-party estate is. The affected users don't know or care which vendor's code was at fault. They know their email address and password are out there, and they expect the brand on the bill to sort it out.
KDDI's response has been reasonably brisk: patch fast, disclose, force resets, publish numbers when they are known. That is roughly what a well-run response looks like. It doesn't undo the exposure, but it does shorten the tail. For everyone else running critical services on someone else's platform, the question worth sitting with is not whether your vendors are competent. It is whether you would find out fast enough if they weren't.