KDDI Data Breach Exposes Up to 14.2 Million Email Logins Across Six Japanese ISPs

Japanese telecommunications giant KDDI Corporation has disclosed a data breach that exposed the email addresses and passwords of up to 14.2 million customers across six internet service providers.

KDDI discovered the compromise on June 17 and responded by blocking the attacker and implementing defensive measures. The investigation found that hackers exploited a vulnerability in an unnamed third-party software used on KDDI’s email system, which also served five other ISPs: STNet, JCOM, Chubu Telecommunications, NIFTY Corporation, and BIGLOBE.

The scale is significant. KDDI is one of Japan’s largest ISPs, with 45,000 employees and $32.4 billion in annual revenue. The 14.2 million figure includes current and former customers, plus inactive accounts that may no longer be in use.

There’s a partial silver lining. KDDI says some passwords were stored in hashed or encrypted form, meaning they can’t be readily abused for account hijacks. But the company didn’t specify what type of encryption was used or what percentage of accounts had passwords stored in plaintext.

KDDI has notified affected ISPs, Japan’s Personal Information Protection Commission, and the Ministry of Internal Affairs and Communications. Customers should reset their email passwords immediately and enable two-factor authentication if available.

References