# KDDI email system data breach

> Live situation record from CLSTR: https://clstr.news/situations/kddi-email-system-data-breach
> Updated: 2026-08-23T23:05:12.000Z. Sources: 6. Developments: 2.

KDDI Corporation has faced administrative guidance from Japanese authorities following a significant data breach involving its email system for internet service providers. 

Initial reports from the Ministry of Internal Affairs and Communications indicated that unauthorized access between May 16 and June 17 affected approximately 7.62 million users. The Ministry criticized the company for inadequate multi-layered defenses, a lack of password encryption, and a delayed response to the incident. 

Subsequent guidance from the Personal Information Protection Commission revealed a larger scope, with the leak affecting approximately 12.23 million users. The Commission noted that passwords for over 7.6 million users were stored in plain text. The breach exploited a software vulnerability, and the Commission found that KDDI failed to implement sufficient technical safety management measures, such as access controls, to prevent lateral movement by attackers. KDDI has been instructed to improve security measures and report on recurrence prevention plans.

## Timeline

### 2026-08-23: KDDI receives administrative guidance following massive email system data breach

Japan's Personal Information Protection Commission issued guidance to KDDI after a breach leaked the IDs and plain-text passwords of over 12 million email service users.

6 sources. https://clstr.news/cluster/kddi-receives-administrative-guidance-following-massive-email-system-data-breach

### 2026-08-09: KDDI receives administrative guidance following massive email data breach

Japan's Ministry of Internal Affairs and Communications issued guidance to KDDI after a breach exposed the email information of approximately 7.62 million users due to inadequate security and slow response.

3 sources. https://clstr.news/cluster/kddi-receives-administrative-guidance-following-massive-email-data-breach

---
Cite as: KDDI email system data breach. CLSTR, https://clstr.news/situations/kddi-email-system-data-breach
