Jul 8, 2026 5 min read
KDDI Data Breach Exposes Millions of Email Logins in Japan
A massive cyberattack on Japanese telecom giant KDDI has exposed the email addresses and passwords of over 12 million users, highlighting the dangers of centralized data storage.
By VoidNumber Team

Imagine waking up to find your private email and password are in the hands of cybercriminals. This is now a reality for over 12 million people in Japan. A massive cyberattack has hit one of the country's largest telecommunications providers, exposing highly sensitive user credentials.
The incident highlights a growing problem for internet users worldwide. We trust major corporations with our private details, but they often fail to protect them. When a telecom giant suffers a breach, the consequences ripple across the entire internet.
The Anatomy of the KDDI Data Breach
The Japanese telecommunications giant KDDI Corporation recently confirmed a massive security incident. The company is the second-largest mobile provider in Japan. It employs over 45,000 people and brings in billions of dollars in annual revenue. Despite its size and resources, its defenses were bypassed.
The breach did not target KDDI’s main mobile carrier network. Instead, the attackers hit an email platform that KDDI operates. This platform manages webmail and storage services for five other Japanese internet service providers (ISPs). The affected ISPs are STNet, Inc., JCOM Co., Ltd., Chubu Telecommunications Co., Inc., NIFTY Corporation, and BIGLOBE Inc.
The attackers gained entry by exploiting a zero-day vulnerability. This is a security flaw that is unknown to the software creators. Because the vendor does not know about it, no patch or fix exists to block the attack. The intrusion began on May 16, 2026. KDDI did not discover the breach until June 17, 2026. For an entire month, the attackers had unrestricted access to customer accounts.
In an official statement, KDDI explained the challenge of dealing with a zero-day flaw:
"As a result of our investigation, as of June 17, 2026, the date of our confirmation, this vulnerability was not recognized by the software vendor."
Once KDDI discovered the intrusion, they blocked the attackers' access. They also patched the vulnerability and deployed endpoint detection and response (EDR) software. However, the damage was already done.
The Numbers: 12 Million Emails Exposed
The scale of the KDDI data breach is truly massive. The company's initial estimates suggested that up to 14.22 million current and former customers were affected. After a deeper forensic audit, KDDI confirmed the exact numbers.
The attackers successfully stole the email addresses of 12,233,087 people. They also made off with the passwords of 7,616,173 users. KDDI noted that some of these passwords were encrypted or hashed. This makes them much harder for hackers to use. However, the company did not specify how many passwords were left in plain text. If your password is in plain text, anyone can read it and log into your account.
The Japanese government took the incident very seriously. Yoshimasa Hayashi, Japan's Internal Affairs Minister, expressed his frustration in a public statement:
"It's extremely regrettable that the incident has had a major impact on users."
KDDI officially reported the incident to the Ministry of Internal Affairs and Communications on July 6, 2026. The company is now working with the affected ISPs to force mandatory password resets for all users.
Why Telecom Companies Are Prime Targets
Why do cybercriminals target telecommunications giants? The answer is simple. These companies act as central hubs for our digital lives. They hold the keys to our communication channels.
When a hacker breaches a standard online store, they might get your shipping address. When they breach a telecom company or an ISP, they get your email and your phone number. These are the two most critical pieces of your online identity.
Telecom companies also suffer from supply chain risks. In this case, five different ISPs relied on a single email platform run by KDDI. This means a single vulnerability in one platform exposed millions of customers across multiple different companies. It is a domino effect. If the central hub falls, everyone connected to it falls as well.
The Ripple Effect: From Email Leak to Identity Theft
A leaked email and password pair is highly dangerous. Hackers rarely use stolen credentials to log into just one account. Instead, they use automated bots to test those logins across thousands of other websites. This tactic is known as credential stuffing.
If you reuse the same password for your ISP email, your social media, and your bank, a single breach can ruin your life. Hackers can gain access to your entire digital footprint in seconds.
Furthermore, having your email address leaked makes you a prime target for phishing. Attackers can send highly convincing messages pretending to be your ISP. Since they know which ISP you use, the fake emails look incredibly authentic. They might claim your bill is overdue or your account is suspended. Once you click their link, they steal your financial information.
How to Protect Your Privacy from Telecom Leaks
You cannot control how secure your internet provider is. You can, however, control how much information you give them. To protect your digital privacy, you must take active steps.
First, stop reusing passwords. Use a reliable password manager to generate a unique, complex password for every single account you own. If one service gets hacked, your other accounts will remain secure.
Second, use two-factor authentication (2FA). This adds an extra layer of defense. Even if a hacker has your password, they cannot log in without a unique code. However, you should avoid SMS-based 2FA whenever possible.
If hackers know your email and your real phone number, they can target you with a SIM swap attack. They trick your mobile carrier into transferring your phone number to a SIM card they control. Once they have your number, they can intercept your SMS verification codes and bypass your security.
The best way to prevent this is to keep your real phone number private. When signing up for online services, do not use your personal cell phone number.
Instead, use temporary virtual phone numbers for SMS verification. Services like VoidNumber allow you to rent temporary numbers for quick sign-ups. You can receive your verification code, complete your registration, and keep your real phone number completely hidden.
If a company you signed up with suffers a data breach, the hackers will only get a temporary virtual number. Your real phone number, your physical location, and your personal identity stay safe. It is a simple, highly effective way to take control of your privacy.
Protect your personal data today. Do not wait for the next major breach to happen.
Keep your real number out of it
Rent a disposable number for your next SMS verification.