Find notable cyber news and cases, enriched with sources, timelines, and signals.

KDDI Corporation hit by network compromise

Incident
First reported
Last updated
Happening score
H score 92
2 unique sources, 3 articles

Summary

Hide ▲

KDDI Corporation confirmed an email-system breach that exposed customer credentials across six Japanese ISPs, putting account access at risk. The intrusion was detected on June 17 and publicly disclosed on June 23. KDDI said as many as 14.22 million email addresses and passwords were likely compromised, making password resets urgent.

Cases

Related Happenings

KDDI email-system credential leak affecting Japanese ISPs

Data Leak
H score98 First: 24.06.2026 15:45 Last: 24.06.2026 15:45 Sources 1

How related: Specifically, KDDI said up to 14.22 million email addresses and passwords have likely been compromised.

About this happening: A KDDI email-system breach exposed customer credentials across six Japanese ISPs, putting up to 14.22 million email addresses and passwords at risk. The compromise was...

Kimsuky QR-code spear-phishing campaign against think tanks and government entities

Campaign
H score42 First: 09.01.2026 07:46 Last: 09.01.2026 07:46 Sources 1

About this happening: The FBI warned that Kimsuky (APT43) is running a QR-code spear-phishing campaign that targets think tanks, academic institutions, and U.S. and foreign government ent...

Timeline

  1. 08.07.2026 14:24 1 articles · 7d ago

    KDDI email platform breached via zero-day on May 16

    Exploitation Observed

    Attackers breached the KDDI email platform used by five Japanese ISPs on May 16 after exploiting a zero-day vulnerability in third-party software, exposing email addresses and passwords across the affected service providers.

    Show sources
  2. 24.06.2026 15:45 1 articles · 21d ago

    KDDI detects intrusion in email system used by Japanese ISPs

    Detection Ioc Update

    KDDI detected unauthorized access to an email system it provides to several Japanese ISPs on June 17 and assessed that the intrusion exploited a vulnerability in third-party software, putting customer email data at risk.

    Show sources
  3. 24.06.2026 15:45 2 articles · 21d ago

    KDDI confirms breach affecting six Japanese ISP email services

    Initial Disclosure

    KDDI publicly confirmed on June 23 that an unauthorized actor had gained access to the email system it provides to several Japanese ISPs, said up to 14.22 million email addresses and passwords were likely compromised, and identified STNet, KDDI Web Communications, JCOM, Chubu Telecommunications, Nifty Corporation, and Biglobe as affected providers.

    Show sources
  4. 24.06.2026 15:45 2 articles · 21d ago

    KDDI contains compromised email system and notifies Japanese authorities

    Mitigation Patch Update

    On June 23 KDDI modified the email system to prevent further damage, implemented technical countermeasures at suspected compromised locations, notified the Personal Information Protection Commission and Japan’s Ministry of Internal Affairs and Communications, and urged customers of the affected email services to change their passwords.

    Show sources