A staggering 12 million people have had their sensitive information compromised in a massive data breach at Japanese telecommunications giant KDDI, one of the country’s largest mobile providers. The breach, which was first discovered on June 17, exposed email addresses and passwords of millions of customers across five internet service providers (ISPs) in Japan.
KDDI, with over 45,000 employees and annual revenue of $32.4 billion, is now working to secure the affected email accounts by changing passwords and implementing additional security measures. The breach was attributed to a zero-day vulnerability in third-party software that attackers exploited on May 16, several weeks before the company discovered the incident.
According to KDDI’s investigation, the attackers gained access to the email addresses of over 12 million people and the passwords of nearly 7.6 million others. Notably, some passwords were stored in hashed and/or encrypted form, which makes them more difficult for hackers to use for account hijacking. However, it remains unclear how many accounts had plaintext passwords or what type of encryption was used.
KDDI has taken swift action to address the breach, deploying Endpoint Detection and Response (EDR) software to detect potential future attacks and conducting a forensic audit on June 23 to ensure that the exploited vulnerability had been addressed. The company has also notified Japan’s Personal Information Protection Commission and the Ministry of Internal Affairs and Communications, and is working closely with affected ISPs to implement security measures.
This breach serves as a stark reminder of the importance of robust cybersecurity practices in protecting sensitive information. With millions of people relying on email services for personal and professional communication, it’s essential that service providers prioritize data security and take proactive steps to prevent such incidents. In this case, KDDI’s prompt response and cooperation with authorities have helped mitigate the impact of the breach.
For individuals and organizations alike, this incident highlights the need for vigilance in protecting digital identity. As cybersecurity threats continue to evolve, it’s crucial to stay informed and take proactive measures to safeguard sensitive information. By staying up-to-date on the latest security best practices and being mindful of potential vulnerabilities, we can all play a role in preventing such breaches from happening in the first place.
In light of this incident, it’s essential for individuals to regularly review their account settings and change passwords frequently, especially if they haven’t used email services recently. By taking these simple steps, we can reduce our exposure to cyber threats and ensure that our sensitive information remains secure.
Source: Bleeping Computer — 2026-07-08