Skip to content

KDDI

Disclosed Jun 28, 20262 months ago12,233,087 affectedUnverified

KDDI email platform zero-day exposes 12.2 million ISP customer logins

KDDI said attackers exploited a zero-day in third-party software on an email system it runs for ISPs including BIGLOBE, NIFTY and JCOM, first estimating up to 14.22 million accounts. It later put exposure at 12,233,087 email addresses and 7,616,173 passwords.

What is known

People affected12,233,087 (as reported by the organization)
DisclosedJun 28, 2026
DiscoveredJun 17, 2026
AttackHacking
Data exposedEmails, Passwords
SectorTelecom · JP
StatusUnverified: not yet confirmed by an official notice, a filing or the organization

Sources

Notices filed

WhereFiledPeople
ResearchtotalJun 2812,233,087
History of this record
  • 2026-09-25 · records: empty to 14220000 · seed source
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.

Everything about KDDI

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.