Japanese telecommunications giant KDDI has confirmed that a zero-day vulnerability in third-party email platform software was exploited on May 16, 2026, resulting in unauthorized access to approximately 12.23 million email addresses and 7.61 million password records. The breach affected KDDI and five subsidiary ISPs — STNet, JCOM, Chubu Telecommunications C, NIFTY Corporation, and BIGLOBE — making it one of the most significant credential exposure events in Japan’s telecom sector. Initial discovery came on June 17 when KDDI detected anomalous access to its email platform.
The attackers exploited the zero-day in the shared email infrastructure approximately a month before detection, giving them extended access to harvest credentials. KDDI has not specified how many of the compromised passwords were stored in hashed or encrypted form versus plaintext. The company has since blocked attacker access, deployed defensive countermeasures, coordinated with all affected ISPs, and is actively advising customers to change their passwords. Japanese authorities have been notified.
The breach has broad implications for credential stuffing campaigns targeting Japanese consumers: with 12 million email addresses and millions of associated passwords now potentially circulating in underground markets, users of these ISPs face elevated risk of account takeover across any service where they reused credentials.
Sources
- BleepingComputer — Japanese Telecom Giant KDDI Says Data Breach Affects 12 Million People
- Security Boulevard — KDDI Confirms Zero-Day Exploit Behind Breach
- TechRadar — KDDI: 12 Million Emails Exposed
Commentary
A zero-day in shared email infrastructure is a nightmare scenario precisely because of the blast radius. KDDI’s architecture — one platform serving six ISPs — traded operational efficiency for a single point of catastrophic failure. The one-month dwell time before detection is particularly troubling: modern attackers don’t just grab data and leave, they spend weeks profiling systems, establishing persistence, and maximizing the value of their access.
The credential exposure here will feed downstream attacks for months. Users of STNet, JCOM, Chubu Telecommunications, NIFTY, and BIGLOBE should assume their email credentials are compromised, change passwords immediately across all services where they’ve reused them, and enable MFA wherever available. For enterprise security teams, this is a good prompt to audit any third-party email or communications infrastructure you rely on — shared platforms are attractive targets precisely because one breach pays dividends across multiple customer populations.
