Japanese telecommunications giant KDDI Corporation has disclosed a data breach impacting an email system it operates for six internet service providers, potentially exposing up to 14.22 million email addresses and passwords. The breach, detected on June 17 and publicly disclosed between June 23-28, was caused by an attacker exploiting a vulnerability in third-party software to gain unauthorized access.

The compromised data spans current, former, and inactive customer accounts across STNet, KDDI Web Communications, JCOM, Chubu Telecommunications, Nifty, and Biglobe. KDDI says it has implemented countermeasures to block further access and is working with the affected providers to notify customers. All impacted users have been urged to change their email passwords immediately.

The scale of this breach is significant — 14.2 million credential pairs is a goldmine for credential stuffing campaigns, phishing, and account takeover attacks. Given the well-documented tendency of users to reuse passwords, the downstream impact could extend well beyond email accounts.

Sources

Commentary

This breach underscores the cascading risk of centralized email infrastructure — when one platform serves multiple ISPs, a single vulnerability puts millions at risk simultaneously. The reliance on unnamed “third-party software” as the attack vector is a pattern we see repeatedly: organizations inherit risk from every dependency in their stack.

For defenders, this is yet another reminder that credential monitoring and forced password rotation after breaches are table stakes. For attackers, 14 million credential pairs from a Japanese telco ecosystem represent a massive opportunity for both targeted and opportunistic campaigns across the region.

By Allan