Top/Articles/KDDI email breach: count corrected to 12,231,954 and resets are done
kddi-isp-mail-breach-cover-en-update

KDDI email breach: count corrected to 12,231,954 and resets are done

KDDI's ISP email system was breached, possibly exposing up to 14.22M email addresses and passwords. @nifty, BIGLOBE and more affected. Here's what to do now.

NewsPublished June 23, 2026 Updated today
Table of contents
Key takeaways

KDDI's ISP email system was breached, possibly exposing up to 14.22M email addresses and passwords. @nifty, BIGLOBE and more affected. Here's what to do now.

CORRECTIONUpdated July 29, 2026

KDDI revised the count on July 21. The "12,233,087" we published has been replaced

On July 21, 2026, KDDI updated its July 6 press release, "Apology and Report on the Unauthorized Access to the ISP Email System" (PDF, Japanese), and rewrote the number of people whose email addresses were confirmed exposed to 12,231,954 (corrected July 21, 2026). The figure we published in our July 7 update, 12,233,087, is the pre-correction number. The gap is 1,133 people β€” under 0.01% of the total β€” but since a number we put in print has changed, here is exactly what moved and why.

ItemWhat we publishedCurrent official figure
Email addresses (total)12,233,08712,231,954 people
of which JCOM2,593,0762,591,943 people
Passwords (total)7,616,1737,616,173 people (unchanged)

The correction originates with JCOM. On the same July 21, JCOM updated its own news release and revised the count for the wholesale ISP email service it supplies to partner cable TV operators down to 118,752 people. The only explanation given is that "a detailed follow-up investigation led to a re-examination of the figure." The difference from the originally published count β€” 1,133 β€” matches KDDI's revision exactly. The 2,473,191 figure for "J:COM NET" itself did not move, so JCOM's new combined total is 2,591,943. The 1,257 password exposures, and the figures for the other five companies, are unchanged.

We also fixed the unit. KDDI and JCOM both count consistently in people (名), not records, and our earlier wording said "records." One tidy detail falls out of the correction: the six companies' email-address figures now sum to exactly 12,231,954, matching KDDI's total. Before the correction, they did not.

The forced password changes are done. Nothing else has moved

Our earlier coverage stopped at the announcement stage β€” "@nifty will disable unchanged passwords from June 26." Here is how it actually ended. The short version: the forced password changes and resets have largely been completed. They were not left as a warning; the providers went through with them.

BIGLOBE reset the BIGLOBE passwords of every member who had not changed theirs, between July 1 and July 9, 2026, and announced on July 9 that the work "completed as scheduled." Anyone who was reset cannot use BIGLOBE Mail or the member portal until they set a new password via phone-based authentication. One distinction matters here: what BIGLOBE reset is the "BIGLOBE password," while the separate "connection password" used for the internet link was explicitly declared out of scope and left alone β€” changing it can knock your line offline.

@nifty went ahead and invalidated the email passwords it could not confirm as changed by the deadline; its address checker page now carries a message stating that the password "has been invalidated on the system side." Invalidation is reversible β€” setting a new email password restores service. JCOM announced that resets for everyone whose password was exposed are complete; customers whose email address alone was exposed are being contacted individually instead of reset.

KDDI itself has not declared completion. Even the July 21 revision of its PDF still reads that forced password changes by the ISPs "are being carried out with completion targeted within a day or two." BIGLOBE and JCOM are the ones who said "done"; KDDI's stated role is supporting each provider's customer response.

For the cleanup after a forced change, KDDI is running a temporary mail-setup call center (0120-487-751, 9:00–20:00 including weekends and holidays) through July 31, 2026. It handles one thing only: reconfiguring Outlook or a phone's mail app after the password changed. The deadline is close, so use it now if you need it.

? A month on, still nothing on these

  • ?Compensation β€” none of KDDI, JCOM, BIGLOBE or KDDI Web Communications has mentioned compensation or a goodwill payment. What has been offered stops at forced password changes and support hotlines. The closest thing to a remedy is BIGLOBE waiving the fee for its email-address change service for the time being β€” a courtesy for people who want a new address, not a payout.
  • ?Secondary damage β€” there is no official report that the leaked data has been abused. That said, @nifty's FAQ states that "there is a possibility that logins were performed using the email password, but we are unable to confirm the details," which is not the same as saying nothing happened.
  • ?The software at fault β€” neither its name nor a CVE ID has been published. KDDI says only that "the software vendor has filed a report with a public agency and is working toward disclosure." It did confirm the flaw was one the vendor itself was unaware of as of June 17 β€” a zero-day.
  • ?The regulatory verdict β€” KDDI filed its report on July 6 in response to MIC's report demand (June 24, Article 166(1) of the Telecommunications Business Act), but no escalation to administrative guidance or a business-improvement order has been announced. The Personal Information Protection Commission has likewise taken no publicly announced action, beyond KDDI stating it reported and consulted.

Relatedly, Nifty updated its "Beware of emails impersonating @nifty" advisory on July 17, adding samples such as "Notice: your password has expired" and "[Urgent] Identity verification for your email account migration." The wording looks tailor-made to ride this incident, but no official source has confirmed a direct link. Piggyback or not, the response is the same: don't click links inside emails.

UPDATEUpdated July 7, 2026

The numbers are confirmed, per-company breakdowns are out, and the regulator issued a report demand

What began as "up to 14.22 million records may have leaked" has firmed up. On July 6, 2026, KDDI announced that its review confirmed the exposure at 12,231,954 email addresses and 7,616,173 email passwords (the address figure was corrected on July 21, so the post-correction value is shown here). "14.22 million" was the possible ceiling; these are the confirmed actual figures. The previously withheld per-provider breakdown also came out β€” including about 397,000 users at Shikoku's Pikara (STNet), showing the damage reached regional services too.

Operator (service)Email addressesEmail passwords
BIGLOBE5,016,4324,631,775
Nifty (@nifty)2,248,7081,862,462
JCOM (J:COM NET etc.)2,591,943
(corrected 7/21, βˆ’1,133)
1,257
Chubu Telecom
(Commufa Hikari)
727,176724,344
KDDI Web Communications
(CPI)
1,250,543none
STNet (Pikara)397,152 users456,159 accounts*
KDDI total12,231,9547,616,173

* Figures are as announced by each company and KDDI, counted in people; the KDDI total and the JCOM row reflect the July 21, 2026 correction. The email-address column now sums to exactly the KDDI total. The password column does not, because STNet alone counts differently β€” it disclosed "456,159 email addresses and passwords belonging to 397,152 users." JCOM's password exposure was limited to 1,257, and no password exposure was confirmed at CPI (rental server).

Regulators moved too. On June 24, Japan's Ministry of Internal Affairs and Communications (MIC) issued a "report demand" (hōkoku-chōshΕ«) under Article 166(1) of the Telecommunications Business Act, requiring KDDI to report the detailed cause, its response to users, and recurrence-prevention measures by July 6. The July 6 confirmation was timed to that deadline. A report demand is the investigative stage; if the response is judged insufficient, it can escalate to administrative guidance or a business-improvement order β€” but as of July 29, no such escalation has been announced. The cause is described as an attacker exploiting a then-undisclosed flaw in third-party software built into KDDI's system. The unauthorized access began around May 16, 2026, and KDDI became aware of it on June 17.

What users should do has not changed: change the email password on any affected service, and change it anywhere you reused the same password. Below is the full write-up of what happened, what an "email password" is, and the exact steps to take.

* Everything below this line dates from the June 24 original and the July 7 update. For what happened to the forced password changes afterwards, see the section above.

On June 23, 2026, KDDI announced that the email system it provides to various internet service providers (ISPs) had been breached, and that email addresses and passwords had leaked (initially reported as up to 14.22 million possible; confirmed on July 6, and the count corrected on July 21, at the figures above). The affected services include email brands many people use every day, such as "@nifty Mail," "BIGLOBE Mail," and "J:COM NET."

The key point that is easy to miss: this does not only concern people who have a contract directly with KDDI (au). Whether your provider is Nifty or BIGLOBE, the system running the email behind the scenes was the same KDDI platform. That is exactly why a single intrusion spread to several companies' services at once. This article walks through what happened, whether your own email is likely affected, and what you should do right now.

What happenedUnauthorized access to KDDI's email system
Confirmed exposure12,231,954 email addresses
7,616,173 email passwords
Affected services@nifty / BIGLOBE / J:COM NET
Pikara / Commufa / CPI (six operators)
Began / detectedBegan ~May 16 / detected June 17
Disclosed / confirmed / correctedDisclosed June 23 / confirmed July 6
count corrected July 21 (βˆ’1,133)
Forced password changeBIGLOBE reset July 1–9, completed
@nifty invalidated unchanged passwords
CauseZero-day flaw in third-party software
(name and CVE still undisclosed)

Why "I don't have a contract with KDDI" doesn't get you off the hook

This is the part most easily overlooked. Many people think of their email as "I'm with @nifty" or "I use BIGLOBE," and never imagine KDDI sitting behind it. In reality, the email functions of these companies ran on a shared system that KDDI provided centrally. The visible brands differ, but the foundation was consolidated into one.

This "invisible shared foundation" is why the damage spread so fast. If the base is one, a hole in it is common to every service on top. From an attacker's point of view, there is no need to break into each company separately; breaching KDDI's system once puts the user data of multiple email services within reach all at once. The sheer size of "up to 14.22 million" comes straight from this structure.

It is also the flip side of convenience. Rather than each provider running its own mail servers, handing the job to a trusted major player makes operations and quality more stable. But the more that "leave it to one provider" advances, the wider a single accident can reach. This incident exposed exactly that weakness. If you only look at the logo of your own provider, you will never notice this kind of risk.

The list of affected email services

Here are the services named in KDDI's announcement, along with the companies that operate them. Check them against the domain (the part after the @) of the email address you use. If you created an email address with any of the services below, you may be among those affected.

OperatorAffected serviceMain users
Nifty@nifty Mail@nifty members
BIGLOBEBIGLOBE MailBIGLOBE members
JCOMJ:COM NET and othersCable TV
internet users
STNetPikara Hikari / Pikara MobileMainly Shikoku region
Chubu TelecommunicationsCommufa Hikari / Business CommufaMainly Chubu region
KDDI Web
Communications
CPI (rental server)Businesses / site owners

The reach spans from Shikoku (Pikara) to Chubu (Commufa Hikari), the nationwide @nifty and BIGLOBE, and even the business-oriented rental server CPI. At first only the combined total was given, but on July 6 the per-company breakdown was confirmed (see the table in the update above). BIGLOBE has the largest count; password exposure was limited at JCOM and not confirmed at CPI, so the details differ by service. You can check whether your own address is affected on each company's "affected address checker" page.

As of July 29, no provider has been added to these six. KDDI's press release also states plainly that its own mobile and fixed-line mail services β€” au Mail, UQ mobile Mail and au one net Mail β€” "are built on separate equipment and suffered no impact or data exposure from this incident." For now, there is no reason to brace for the scope widening.

It wasn't just email addresses

What deserves the most weight in this announcement is that the data possibly exposed includes not only email addresses but passwords too. An email address alone might mean nothing worse than more spam. But when passwords leak alongside them, the situation gets a step more serious.

The scary part is not the email takeover itself, but the chain reaction. Email addresses are reused as the login ID for all kinds of services β€” online shopping, social media, online banking. That is where password reuse becomes the problem. If you use the same email-and-password combination on other services, attackers can try that pair one service after another and hijack accounts in a cascade. This technique of automatically testing huge lists of stolen IDs and passwords is called a "credential stuffing (password list) attack," and it almost always follows in the wake of a breach.

On top of that, having your email taken over is itself a gateway to the next round of damage. Many services run their "forgot your password" resets through email, so if your mailbox is seized, the reset links delivered there can be used to break into yet more accounts. Email is something like the "spare-key cabinet" of your online life; once it is breached, the impact does not stay in one place. That is precisely why the steps below are worth hurrying.

The timeline so far

According to KDDI, the company became aware of the unauthorized access six days before disclosure. Here is the sequence from detection to disclosure and the report to the authorities.

← Swipe to move

There is a six-day gap between detection and disclosure. Rather than a sign of hiding information, this is more naturally read as the time it took to pin down the scope and prepare the report to the authorities. For users, however, it means there were six days during which "my password may have leaked." Even while waiting for follow-up news, there is no harm in getting the steps below underway first.

Why was a company as big as KDDI breached?

By KDDI's account, the entry point was a vulnerability in third-party software used within its system. A vulnerability is a design or implementation flaw lurking in a program β€” a hole that, when exploited, allows operations that should not be possible. Exactly which software and which flaw has not been disclosed.

Here lies another structure that is hard to see. Large systems are not built entirely from scratch in-house; they are assembled from off-the-shelf software and components. In other words, no matter how thoroughly you harden your own security, if a built-in external part has a hole, you can be breached through it. To a user it is "email entrusted to KDDI," yet the inside depends in turn on software made by someone else. It is a double structure: the party you entrusted depends, in turn, on yet another party.

This pattern of "breached through an external part or an outsourced partner" is common to recent large incidents. At the streaming service Crunchyroll, it was not its own systems but an outsourced partner that became the entry point, leaking information on roughly 6.8 million people. In Japan, too, cases where "the periphery, not the core" becomes the hole keep coming, as when Awa Bank had a neglected test environment exploited and leaked 27,000 records. Defenders must keep every component safe at all times, while attackers only need to find one hole. This asymmetry is the fundamental reason even giant companies get breached.

What users should do right now

Even at the "may have leaked" stage, there are precautions you can take. Since passwords are among the data at risk, the top priority is to change the password for the affected email service, and also change it on any other services where you reused the same password. Here is the order.

1. Change the password for the affected email service. If your email service is in the list above, change that password first. You can do this from each company's support pages (such as BIGLOBE and @nifty). Make the new password a unique one you do not use anywhere else.

2. Change other services where you reused it. The most dangerous case is using the same password for online shopping, social media, or online banking. If the leaked pair is tested there, those accounts can be broken into in a cascade. If anything comes to mind, change those to separate passwords too.

3. Turn on two-factor authentication. This is a setting that, in addition to your password, requires something like a confirmation code sent to your phone. Even if your password leaks, this goes a long way toward blocking unauthorized logins. Always switch it on for services that support it.

4. Beware of "piggyback" fake emails. After incidents like this, fake emails that prey on anxiety surge. They use lines like "an apology for the data leak" or "verify your password now" to lure you to fake login pages. Do not click links inside emails; the safe approach is to open each company's official site yourself from your own bookmark and proceed there. It is also worth checking whether any login notifications you don't recognize have arrived.

5. Fix your mail client settings. After you change a password β€” or have it changed for you β€” Outlook, Thunderbird and your phone's mail app will keep failing until you enter the new one there too. This is where most people get stuck, which is why KDDI is running a temporary mail-setup call center (0120-487-751, 9:00–20:00, weekends and holidays included) through July 31, 2026. It covers configuration only, and the deadline is near.

The forced password changes are now largely complete at each provider, and no announcement has expanded the affected set beyond the six operators. As of July 29, none of the companies has said anything about compensation.

What we know, and what we don't yet

βœ“ Confirmed facts

  • βœ“KDDI's email system provided to ISPs was breached (ITmedia)
  • βœ“Figures confirmed July 6 and corrected July 21: 12,231,954 email addresses and 7,616,173 email passwords (KDDI press release, PDF)
  • βœ“The 1,133 correction traces to JCOM's re-examination of its wholesale ISP mail service for cable operators (JCOM)
  • βœ“The per-company breakdown is out. BIGLOBE is largest; password exposure was limited at JCOM and not confirmed at CPI
  • βœ“The scope is still six operators. KDDI states au Mail, UQ mobile Mail and au one net Mail run on separate equipment and were unaffected
  • βœ“Cause was a flaw the software vendor itself did not know about β€” a zero-day; access began ~May 16, detected and patched June 17
  • βœ“Forced password changes are complete. BIGLOBE reset July 1–9 and announced completion; JCOM completed resets for affected customers (BIGLOBE)
  • βœ“MIC issued a report demand on June 24 under Article 166(1); KDDI filed its report on July 6

? Not yet disclosed

  • ?Whether the leaked data has actually been misused β€” no secondary-damage reports, though @nifty says unauthorized logins "cannot be ruled out" and it cannot confirm details
  • ?The name of the exploited third-party software and the details of the flaw β€” undisclosed; the vendor has filed with a public agency and is working toward disclosure
  • ?Whether passwords were encrypted or stored closer to plain text β€” unclear from public information
  • ?Any compensation policy β€” no mention from KDDI, JCOM, BIGLOBE or KDDI Web Communications
  • ?Whether MIC will escalate to administrative guidance or an order β€” no announcement as of July 29
  • ?Any action by the Personal Information Protection Commission β€” KDDI says it reported and consulted, but the commission has announced nothing

Frequently asked questions

Q. My email suddenly stopped working. Have I been hacked?

More likely you were caught by a forced reset. BIGLOBE reset the passwords of all members who had not changed theirs between July 1 and 9, and @nifty invalidated email passwords it could not confirm as changed. Set a new password, then enter it in your mail client or phone app and service returns. If the settings defeat you, KDDI's mail-setup call center (0120-487-751) is open through July 31.

Q. Will there be compensation?

As of July 29, none of KDDI, JCOM, BIGLOBE or KDDI Web Communications has mentioned compensation or a goodwill payment. What they offer is password changes, resets and support hotlines. The nearest thing is BIGLOBE waiving the fee for its email-address change service for the time being. Whether any policy follows is unknown.

Q. I only use an au smartphone. Does this concern me?

What has been named as affected here are the "email services of various ISPs," such as @nifty and BIGLOBE. KDDI's press release states that au Mail, UQ mobile Mail and au one net Mail are built on separate equipment and suffered no impact or exposure. That said, if you separately created an email address with one of these providers, you may be affected.

Q. If I change my password, am I safe?

Changing the password for the affected service is the top priority, but it may not be enough on its own. If you reuse the same password on other services, you need to change it there as well. Combine this with enabling two-factor authentication and staying alert to piggyback fake emails.

Q. Will KDDI contact me?

KDDI is proceeding with reports to the Personal Information Protection Commission and the Ministry of Internal Affairs and Communications, and the service operators may issue guidance to users. However, fake emails impersonating that very guidance also circulate easily, so don't click links inside emails β€” opening the official site yourself is the safe approach.

Q. Why were so many services affected at once?

Because each company's email functions ran on KDDI's shared system. With the foundation consolidated into one, a single intrusion there spread simultaneously to the multiple services riding on top of it.

Update history

  • β–ΈJuly 29, 2026: exposure count corrected. KDDI updated its press release on July 21 to put the email-address figure at 12,231,954, so the body text, tables and timeline have been replaced (we previously published 12,233,087; the gap is 1,133). The correction originates with JCOM, which revised its wholesale ISP mail service for cable operators to 118,752. Units were aligned to the official "people" count, the aftermath of the forced password changes was added (BIGLOBE reset July 1–9 and completed, @nifty invalidated unchanged passwords, JCOM completed resets for affected customers), and the absence of any announcement on compensation, secondary damage, the software at fault and regulatory escalation was set out.
  • β–ΈJuly 7, 2026: added the follow-up after KDDI's July 6 confirmation β€” the confirmed figures, the per-company breakdown for BIGLOBE, @nifty, JCOM, Chubu Telecom, STNet (Pikara) and CPI, MIC's report demand of June 24, and the May 16 start date.
  • β–ΈJune 24, 2026: first published, following KDDI's June 23 announcement of a possible leak of up to 14.22 million records.

Sources

avatar-m-1

Makoto Horikawa

Backend Engineer / AWS / Django