🚨 BREAKING NEWS

KDDI Confirms Data Breach Affecting More Than 12 Million Users

Attackers exploited a zero-day vulnerability in third-party email software, exposing millions of customer accounts across multiple Japanese Internet Service Providers.

📅 Published
July 2026
📖 Reading Time
4 min
🏷 Category
Data Breach
Threat Level
High

⚡ Quick Summary

  • KDDI disclosed unauthorized access affecting its email platform.
  • The breach originated from a zero-day vulnerability in third-party software.
  • More than 12.23 million email addresses were exposed.
  • Approximately 7.61 million passwords were also compromised.
  • Password reset procedures have been initiated for affected users.

📰 What Happened?

Japanese telecommunications company KDDI has confirmed a large-scale cybersecurity incident after attackers exploited a previously unknown vulnerability affecting third-party software used within its email platform.

Unlike attacks targeting customer devices directly, this incident affected infrastructure supporting multiple Internet Service Providers (ISPs). Because several providers relied on the same software platform, a single vulnerability resulted in millions of customer accounts being exposed.

According to KDDI, approximately 12.23 million customer email addresses and around 7.61 million passwords were accessed before the intrusion was contained.

📅 Timeline

May 2026
Attackers begin exploiting an unknown vulnerability.



June 17
Suspicious activity detected.



Incident Response Activated
Affected systems isolated.



Forensic Investigation
Zero-day exploitation confirmed.



Public Disclosure
KDDI notifies customers.

🔍 Technical Analysis

The compromise was traced to a previously unknown vulnerability affecting third-party software integrated into KDDI’s email service infrastructure.

Because the vulnerability existed within shared software rather than KDDI’s own customer-facing applications, multiple Internet Service Providers relying on the same platform became affected.

Incidents of this nature demonstrate how vulnerabilities within shared technologies can rapidly scale beyond a single organization.

📊 Impact

Affected Users 12.23 Million
Passwords Exposed 7.61 Million
Industry Telecommunications
Country Japan 🇯🇵
Current Status Contained

🏢 Company Response

Following detection of the intrusion, KDDI blocked unauthorized access, initiated a forensic investigation, and began notifying affected Internet Service Providers and customers.

The company also launched password reset procedures and stated that there is currently no evidence of continued unauthorized activity after containment measures were implemented.

🔎 What’s Next?

  • Customer notifications continue.
  • Password reset campaign underway.
  • Additional forensic analysis remains in progress.
  • Security monitoring has been strengthened across affected infrastructure.
  • Further updates will be provided if new findings emerge.

📰 Source

SecurityWeek • “12 Million Impacted by Data Breach at Japanese Telco KDDI”