All Breaches
May 16, 2026 Verified Telecommunications

KDDI ISP E-posta 2026 Data Breach

The KDDI ISP email-system breach of 2026 resulted from exploitation of a third-party software flaw in shared email infrastructure that the Japanese telecom company provided to internet service providers. KDDI's updated official notice confirms exposure of 12,231,954 people's email addresses and passwords belonging to 7,616,173 people within that group.

Unauthorized access began at some providers on May 16, 2026. KDDI detected the incident on June 17, modified the system and applied technical defenses that day, and made its first public announcement on June 23. On July 21 it corrected the email count in its detailed July 6 report to 12,231,954; LeakData uses this latest official figure.

Confirmed Data Types and Counts

The two confirmed data types are email addresses created within the affected mail system and system passwords. The 7,616,173 password records are a subset of the 12,231,954 email addresses and the figures must not be added together. The total affected population is therefore not 19.8 million but at most 12,231,954 people.

KDDI did not report exposure of names, postal addresses, phone numbers, payment details, or government identity numbers, so those fields are not added as data classes. The combination of an email address and password still creates account-takeover risk on other services where the password was reused and on accounts that can be reset through the compromised mailbox.

The Affected ISP Infrastructure

The event affected a KDDI-developed platform for ISPs that combined email-account administration, sending and receiving, webmail, and message storage. Public reporting identifies STNet, JCOM, Chubu Telecommunications, NIFTY, and BIGLOBE as the five providers using the infrastructure. Users should confirm the affected domain through their own provider's notice.

KDDI's au Mail, UQ mobile Mail, and au one net Mail services operated on separate equipment, and the company said they had no impact or information leakage from this incident. It would be inaccurate to treat every KDDI-branded mailbox as breached. ISP customers who receive a notice or mandatory reset should, however, treat their account as part of the affected group.

How the Zero-Day Was Exploited

Attackers exploited a vulnerability in third-party software that KDDI had installed as part of the system. The software vendor did not know about the flaw when KDDI detected the incident on June 17, making it a zero-day exploitation event. The vendor subsequently reported the flaw to a public authority and began work toward disclosure and remediation.

KDDI did not identify the software, provide a CVE, or attribute the intrusion to a threat actor. This record does not add an unverified product name, attacker group, or exploit detail. The defensive lesson is that third-party components need network separation, behavioral monitoring, least privilege, and unusual-data-access alerts even during the period before a patch exists.

KDDI and ISP Response

KDDI modified the system and ended the suspicious access on June 17. It completed EDR deployment on all servers controlling external communications by June 21, and a third-party forensic review on June 23 found no suspicious traces beyond the disclosed vulnerability. The company also submitted the requested formal report to Japan's communications ministry.

KDDI worked with affected ISPs to change customer passwords. Many frequent users had completed the change, and mandatory resets were planned for remaining accounts, including rarely used mailboxes. Customers should open the provider's official site directly rather than trusting an unexpected email containing a password-reset link.

Securing the Email Account

Replace the affected ISP password immediately with a long, unique value. If the old password was used on another site, create a different password on every such service, starting with the email account. A password manager prevents reuse; enable multi-factor authentication where available and prefer an authenticator application or security key over SMS.

Review active sessions, automatic forwarding rules, recovery addresses, application passwords, and connected applications in the mailbox. Remove unfamiliar rules, close all sessions, and inspect banking, shopping, social-media, and cloud accounts that can be reset through email. Unexpected password-reset messages may indicate that someone is testing the old credentials.

How to Interpret This LeakData Record

The 12,231,954 value is KDDI's corrected July 21, 2026 email-address count. The 7,616,173 passwords form a subset and are not added again to the total. No email or password rows were imported into LeakData, so the absence of a search result does not override an affected-provider notification.

This entry covers only the May–June 2026 breach of the shared platform supplied to ISPs; it does not mark the separately hosted au, UQ mobile, or au one net services as affected. If KDDI or the software vendor later publishes a CVE, product name, actor attribution, or corrected scope, the record should be revised only to match that newly verified information.

12.2 Million
Affected Accounts
2
Data Types
Critical
Severity
Yes
Verification

Exposed Data Types

2
Email addresses
Passwords

Additional Information

Added DateJuly 26, 2026
Breach DateMay 16, 2026
Domainkddi.com
SourceSoftware vulnerability
Last Content UpdateJuly 26, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information