A KDDI data breach has put up to 14.2 million ISP email logins at risk across Japan
Japanese telecommunications company KDDI confirmed a data breach on June 17, 2026, in which attackers gained unauthorized access to a system shared by six ISP mail services. Up to 14.22 million email addresses and associated passwords may have been exposed as a result.
Why this matters: Email login credentials are not just one piece of data. They are often the key to everything else — password resets, banking alerts, personal messages, account recovery. Fourteen million people in Japan may now have that key in someone else's hands. The fact that a single compromised system touched six different ISPs at once shows how shared infrastructure quietly concentrates risk. If your credentials were in that system, the damage is not limited to your inbox.
Who should care: Cybersecurity · Privacy officers · Administrators
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.