Protect.Computer
NEWS

Email breach at six Japanese ISPs exposes 14 million passwords

· 1 min read · Got hacked Data hijack
Email breach at six Japanese ISPs exposes 14 million passwords

Japanese telecom giant KDDI disclosed that attackers exploited a flaw in third-party software to break into email systems shared with five partner providers: STNet, JCOM, Chubu Telecommunications, NIFTY, and BIGLOBE. Up to 14.22 million accounts — including current, former, and inactive ones — may have had email addresses and passwords exposed. The breach was discovered on June 17, 2026, and KDDI says some passwords were stored in hashed or encrypted form, though the company has not confirmed whether all were protected.

If you have or ever had an email account through any of those six providers, treat your credentials as compromised. Changing your password now and turning on two-step login is the fastest way to lock out anyone who may have grabbed your details.

How to check if you’re affected

Affected products include the email services of KDDI, STNet, JCOM, Chubu Telecommunications (CTY), NIFTY, and BIGLOBE. If you have an active or former email account with any of these providers, your address and password may have been exposed.

  1. Reset your email password right away. Go to your provider’s account settings and choose a strong, unique password you’ve never used elsewhere.
  2. Enable two-step verification. This adds a second check (usually a code sent to your phone) so even a stolen password can’t unlock your account alone.
  3. Watch for notice emails from your provider. KDDI has notified Japan’s data-protection authorities and may contact affected customers directly.
  4. Check if the same password is used anywhere else. If so, update it on those sites too — attackers often try leaked passwords on popular services like banking and shopping apps.

Sources

Related reading