12 Million Impacted by Data Breach at Japanese Telco KDDI

A massive data breach at Japanese telco KDDI has compromised the sensitive information of over 12 million individuals. The incident occurred on June 17 when hackers exploited a zero-day vulnerability in software used by five internet service providers (ISPs) that rely on KDDI’s email infrastructure.

The affected ISPs include STNet, JCOM, Chubu Telecommunications, NIFTY, and BIGLOBE, which collectively serve millions of customers. Fortunately, KDDI’s mobile and fixed-line internet email services, which operate on separate infrastructure, were not impacted by the attack.

According to KDDI, hackers gained unauthorized access to a system that manages emails for the affected ISPs. The company has revealed that the breach was made possible by a zero-day vulnerability in software implemented as part of the system. A zero-day vulnerability is a previously unknown flaw in software that can be exploited by attackers before a patch or fix becomes available.

KDDI’s notice explains that several ISPs have been affected by the bug’s exploitation since May, and that the vendor is now working on a patch for the zero-day. The company has confirmed that the hackers compromised the email addresses of 12.2 million people, as well as the passwords of 7.6 million individuals.

In response to the breach, KDDI says it has been working with the affected ISPs to prompt password resets and that customers who use their email addresses on a regular basis have already updated their login information. A mandatory password reset will be completed for all affected email accounts within the coming days.

While KDDI has evicted the hackers from its systems, the company is taking proactive measures to ensure that no additional vulnerabilities exist in the involved software. To this end, it will thoroughly inspect the software and work with the ISPs to transition to more secure communication technologies.

The recent breach at KDDI highlights the importance of robust cybersecurity practices, particularly for organizations that handle sensitive customer data. It also underscores the need for companies to stay vigilant in monitoring their systems for potential vulnerabilities and to promptly address any issues that arise.

As a result of this incident, it’s essential for customers to be proactive about protecting their online accounts. If you use email services provided by one of the affected ISPs, we recommend taking immediate action to update your login credentials and regularly monitor your account activity for suspicious behavior.


Source: SecurityWeek — 2026-07-09