:

DATA BREACH HITS 14.2M LOGINS AT JAPANESE ISPS

AI DESK1 MIN READ
SUN, JUN 28, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Japanese telecom KDDI Corporation disclosed a data breach exposing up to 14.2 million email logins. Threat actors accessed an email system shared by KDDI and five other internet service providers in the country.

KDDI, one of Japan's major telecommunications operators, confirmed the security incident affected its email infrastructure used across multiple ISPs. The breach exposed customer email logins and associated credentials. The incident highlights the cascading risks of shared infrastructure among providers. A compromise at a single point of access can impact millions of users across multiple organizations. KDDI has not disclosed specific details about the breach timeline, the identity of the threat actors, or whether the exposed credentials have been actively exploited. The company is investigating the incident and working to secure affected systems. Users of the affected ISPs are advised to monitor their accounts for suspicious activity and change passwords if they use credentials associated with the compromised email systems. This incident adds to a growing list of large-scale data breaches affecting telecommunications providers globally.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

PaperCut has released a second emergency security update for its NG and MF print management software after researchers discovered bypass methods for the initial fixes. The vulnerabilities are currently being exploited in the wild.

JUST NOWSecurity Desk

A 68-year-old has been sentenced to over six years in prison in the U.K. for operating an illegal IPTV service that generated £980,812 ($1.3 million) over three years.

3H AGOIndustry Desk

A detailed analysis examines how the internet has shifted toward predatory practices, drawing significant engagement from tech community members on Hacker News with 227 points and 120 comments.

4H AGOIndustry Desk

A critical vulnerability in the popular GiveWP WordPress donation plugin allows unauthenticated attackers to execute arbitrary commands on hosting servers. The maximum-severity flaw requires immediate patching.

4H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.