---
answer: direct
beat: dev-practices
source: 1 article · updated: July 7, 2026
---

What happened in the KDDI data breach?

Attackers exploited a vulnerability in unnamed third-party software to reach a shared email platform serving six Japanese ISPs — KDDI, STNet, JCOM, Chubu Telecommunications, NIFTY, and BIGLOBE. KDDI disclosed that the email addresses and passwords of up to 14.2 million current, former, and inactive customers may have been exposed.

Answered in

One Vendor Flaw Just Exposed 14.2 Million Logins Across Six Japanese ISPs

A flaw in one unnamed vendor's software let attackers into a shared email platform, exposing up to 14.2 million accounts across six Japanese ISPs.

Crashtech Editorial July 7, 2026 Development Best Practices

Read the full analysis

Other questions this article answers

More development best practices questions

Every answer on Crashtech is written by the editor of the article it comes from — never auto-summarised. Browse all answers or the Development Best Practices beat.