ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Hackers breach Japanese telecom giant KDDI Corporation's email systems, exposing millions

A critical vulnerability in business software led to a data breach at one of Japan’s largest telecommunications companies, compromising email accounts across multiple internet service providers.

Linked InXFacebook
bookmark_borderSave to Library

KDDI Corporation, a major Japanese telecom operator, discovered on June 17 that attackers had gained unauthorized access to an email system used by six affiliated internet service providers. The company identified a vulnerability in third-party software running on the email platform and immediately blocked the attacker and deployed defensive measures.


The scope of the breach remains under investigation, but KDDI said email addresses and passwords belonging to up to 14.2 million customers may have been exposed. This figure includes current and former customers, as well as inactive accounts no longer in active use. The affected internet service providers are STNet, KDDI Web Communications, JCOM, Chubu Telecommunications, Nifty, and BIGLOBE.


KDDI said some passwords were stored in hashed or encrypted form, limiting their immediate utility to attackers. The company did not specify what encryption methods were used or the percentage of accounts with plaintext passwords.


KDDI is among Japan’s largest telecommunications companies. It operates mobile, fixed-line, broadband, cloud, and data center services, generating annual revenue around 5.9 trillion yen, or approximately $40 billion. The company has more than 60,000 employees.


The breach prompted KDDI to begin notifying affected internet service providers starting June 17. The company also reported the incident to Japan’s Personal Information Protection Commission and the Ministry of Internal Affairs and Communications, as required by law.


KDDI is coordinating with the affected internet service providers to implement additional security measures. The company advised all customers who may have been affected to reset their email passwords immediately and enable two-factor authentication where available.

Linked InXFacebook
bookmark_borderSave to Library
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543