Data breach exposes up to 14.2 million email logins at six ISPs
KDDI disclosed a data breach that exposed an email system used by five partner ISPs, potentially affecting up to 14.2 million email addresses and passwords. The breach was discovered on June 17, with the attacker blocked and defenses deployed afterward. It stemmed from a vulnerability in an unnamed third‑party software; some passwords were hashed or encrypted, while others may have been exposed. KDDI is notifying the affected ISPs and regulators and urging users to reset passwords and enable 2FA where available.

Data breach exposes up to 14.2 million email logins at six ISPs
OverviewA data breach at a major Japanese telecommunications group has exposed the email accounts of millions of users across several affiliated internet service providers. The incident centers on unauthorized access to one of the company’s email systems that is used by a network of ISPs in Japan. The event was discovered on June 17, and immediate steps were taken to block the attacker and strengthen defenses. The breach appears to involve an exploitation of a vulnerability in an unnamed third‑party software used within the system.
Timeline of events
- Discovery: June 17 — the breach was detected and containment measures were begun.
- Immediate action: Access was blocked for the attacker, and defensive controls were strengthened on the affected system.
- Ongoing investigation: The company states that the investigation is still underway to determine the full extent and exact numbers involved.
Scope and exposure
- The breach affected one core email system that serves five other ISPs, forming a total network of six operators including the primary company.
- The likely scope includes both current and former customers, as well as accounts that may no longer be active.
- The data exposed potentially includes email addresses and passwords of up to 14.22 million users.
- Password storage posture varied: some passwords were stored in hashed and/or encrypted form, which can mitigate immediate misuse, while others may have been exposed in plaintext. The exact mix and the encryption method used have not been disclosed.
The affected ISPsThe incident explicitly impacted the following five internet service providers connected to the compromised system:
- STNet, Inc.
- JCOM Co., Ltd.
- Chubu Telecommunications Co., Inc.
- NIFTY Corporation
- BIGLOBE Inc.
Security details and uncertainties
- The attackers exploited a vulnerability in third‑party software integrated into KDDI’s email infrastructure.
- While defensive measures have been put in place, there remains a possibility that attackers gained access to some users’ email addresses and passwords as a result of the incident.
- The company emphasizes that the full number of affected accounts is not yet finalized, and the situation is subject to change as the investigation progresses.
Corporate response and regulatory engagement
- Communication with stakeholders: Since the discovery, KDDI has been coordinating with the five affected ISPs to implement additional security measures and mitigate risk.
- Regulatory notifications: Authorities in Japan, including the Personal Information Protection Commission and the Ministry of Internal Affairs and Communications, have been notified as part of the incident response.
- Ongoing collaboration: The operator is working with the impacted ISPs to reinforce defenses and reduce the likelihood of future exposures stemming from the same vulnerability.
Data at risk and potential implications
- Email addresses: The exposure includes email addresses associated with the affected accounts, which could be used in targeted phishing or credential‑stuffing campaigns.
- Passwords: Depending on how passwords were stored, there is a risk that some credentials could be misused if they were exposed in plaintext or weakly protected. The existence of hashed or encrypted passwords provides some barrier to immediate exploitation, though the strength and type of encryption are not specified.
- Scope of impact: The figure covers current and former customers as well as inactive accounts, expanding the potential reach of any credential compromise beyond active users.
What this means for customers and the broader ecosystem
- The incident underscores the risk inherent in third‑party software integrated with critical infrastructure and the potential for cascading exposure across partner services.
- Even when some data is stored securely (e.g., hashed or encrypted passwords), the exposure of associated email addresses can facilitate social engineering or credential reuse attempts on other services.
- The evolving nature of the investigation means that numbers and affected services may be updated as new information becomes available.
Bottom line status
- The breach has been identified and containment actions have been executed, with ongoing investigations and cross‑vendor collaboration to strengthen defenses.
- Regulatory bodies have been informed, and affected ISPs are working to mitigate risk and prevent recurrence.
- At this stage, the precise count of compromised accounts remains to be confirmed, but the upper bound cited is up to 14.22 million users across the network of six ISPs involved in the incident.


