S 12,231,954 peopleThe Personal Information Protection Commission issued guidance to KDDI over a leak of IDs and passwords from an ISP mail system through a vulnerability exploit. The number of affected persons is 12,231,954, of whom 7,616,173 had passwords stored in plain text.
Unauthorized access & data leakConfirmedOfficial statement
S 1,360,563 accountsWhile investigating unauthorized access to its rental server service, the company found that its sales management system, which holds contract information, may also have been accessed, and member information of up to 1,360,563 accounts may have been viewed or obtained. For 30 of them, hashed passwords may also have been accessed.
Unauthorized access & data leakPossibleOfficial statement
B 77,619 recordsIn February 2026, a server managing personal information was accessed by ransomware attackers, leaving 77,619 records with names, addresses and other data, plus 1,360 name-only records, viewable by the intruder. No external leak or misuse has been confirmed.