KDDI
Disclosed Jun 28, 20262 months ago12,233,087 affectedUnverified
KDDI email platform zero-day exposes 12.2 million ISP customer logins
KDDI said attackers exploited a zero-day in third-party software on an email system it runs for ISPs including BIGLOBE, NIFTY and JCOM, first estimating up to 14.22 million accounts. It later put exposure at 12,233,087 email addresses and 7,616,173 passwords.
What is known
| People affected | 12,233,087 (as reported by the organization) |
|---|---|
| Disclosed | Jun 28, 2026 |
| Discovered | Jun 17, 2026 |
| Attack | Hacking |
| Data exposed | Emails, Passwords |
| Sector | Telecom · JP |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
Sources
| Source | |
|---|---|
| Data breach exposes up to 14.2 million email logins at six ISPsbleepingcomputer.com · News | News |
| Telco giant KDDI says data breach affects over 12 million peoplebleepingcomputer.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Jun 28 | 12,233,087 |
History of this record
First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.