KDDI confirms data breach affecting corporate email system
Up to 14.22 million users' email addresses and passwords may have been exposed following external intrusion into the provider's corporate services.

Japanese telecommunications provider KDDI has confirmed that its email system, designed for corporate clients, was subjected to unauthorised external access. The company announced on 23 June 2026 that the breach potentially compromised the email addresses and passwords of up to 14.22 million users.
The incident involves a business-to-business service rather than personal mobile phone accounts. KDDI stated that the unauthorised access occurred on the same day, with the official announcement released at 17:13 local time. The telecommunications firm has not yet disclosed the specific method used by the perpetrators to gain entry into the system.
Data exposure is limited to email addresses and passwords associated with the corporate email service. It remains unconfirmed whether the leaked passwords were stored in encrypted format or in plain text, a detail that would significantly influence the severity of the security risk for affected organisations.
The exact number of impacted users is currently described as "up to" 14.22 million, indicating that the final count may vary as investigations continue. KDDI has not provided details regarding the identity of the attackers or the extent to which the data may have been misused or distributed externally.
This breach is distinct from other cybersecurity incidents involving the company and does not involve personal mobile account data or billing details. As of the time of the announcement, the full extent of the data misuse remains unverified.


