KDDI Confirms Breach: 7.6 Million Passwords and 12 Million Emails Leaked Across ISPs

- KDDI's mail system for ISP operators suffered unauthorized access
- About 12.23 million email addresses and 7.61 million passwords confirmed leaked
- BIGLOBE (~5.02 million) and Nifty (~2.25 million) users are affected
- Credential-stuffing risk spikes; change passwords and drop reuse now
Another hole in Japan's internet plumbing: KDDI confirmed that its mail platform serving ISP operators was breached, leaking about 12.23 million email addresses and 7.61 million passwords—most of the initially feared 14.22 million. Downstream, BIGLOBE reports roughly 5.02 million users hit and Nifty 2.25 million.
Mass password leaks breed credential stuffing—one stolen pair tried against banks, brokerages and shopping sites. Japanese ISP mailboxes skew older with high password reuse, handing fraud rings a precision list in the tens of millions. Anyone with Japanese accounts should change ISP passwords, audit reused credentials on financial services, and enable two-factor authentication. For markets, stacked atop recent telecom and government incidents, Japan's security-spending gap remains the durable demand story for cybersecurity names—defenders' budgets are always drafted by their attackers.