Major Email Password Breach in Japan Affects Up to 14.2 Million Users: What to Do
If you use an ISP email service in Japan through KDDI or related providers, your email address and password may have been exposed to attackers.
Source
DataBreaches.net
Original headline: A KDDI data breach has put up to 14.2 million ISP email logins at risk across Japan
Plain-English summary by GetCyberRight. Read the full report at the source above.
Japanese telecommunications company KDDI discovered that attackers gained unauthorized access to a system that handles email services. The breach potentially exposed up to 14.22 million email addresses and passwords. KDDI confirmed the incident on June 17, 2026, and repaired the affected system the same day. The breach impacted email services across six different internet service providers in Japan.
If you use email services from KDDI or one of the six affected ISP providers in Japan, your email address and password may have been exposed.
Stay one step ahead of scammers
Weekly cybersecurity briefings for families. No spam, just the threats that matter and what to do about them.
This means attackers could potentially access your email account, read your messages, and use your account to send emails pretending to be you. They could also try using your password on other websites if you reused it. You should take action immediately if you use any of these email services.
Here is what to do right now:
- Change your email password immediately. Create a strong, unique password that you do not use anywhere else.
- Check your email account for any suspicious activity, such as sent emails you did not write or unfamiliar login locations.
- If you used this same password on any other websites or apps, change those passwords too.
- Enable two-factor authentication on your email account if available. This adds an extra layer of security beyond just your password. To protect yourself going forward, use a different password for every important account, especially email and banking. Consider using a password manager to help you keep track of unique passwords. Set up two-factor authentication on all accounts that offer it. Be extra cautious about emails asking you to click links or provide personal information, as attackers may use the exposed email addresses to send phishing messages.
Curated from trusted cybersecurity sources by GetCyberRight
Source: DataBreaches.netStay ahead of cyber threats
Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.
More articles
Millions of Email Passwords Exposed in Japan Internet Provider Breach: Check Your Account
If you use internet service in Japan from KDDI or related providers, up to 14.2 million email passwords may have been stolen. You need to change your password now.
2 min readNew Zealand Pharmacy Accidentally Posted Private Patient Messages Online
A Wellington pharmacy accidentally made private patient messages visible on the internet. The pharmacy says it has now removed the information and is contacting affected patients.
2 min readNew Zealand Pharmacy Accidentally Posted Patient Messages Online: Check If You Were Affected
Unichem Petone pharmacy in Wellington leaked private patient messages on its website. The pharmacy says it has removed the information and is contacting affected patients.
2 min read_Aleksei_Gorodenkov_Alamy.jpg?width=720&quality=80&disable=upscale)
Your School May Have Exposed Student Data Through Outside Vendors. Here's What Parents Should Do
Schools and colleges are facing data breaches not from their own systems, but from outside companies they work with. Student information is at risk.
2 min read