Skip to content
The Cyber Security Place

Twelve million addresses, seven million passwords, two different problems

Event dated 17 June 2026 · Published 2 September 2026 · 3 sources

The Japanese operator KDDI disclosed that unauthorised access detected on 17 June 2026 exposed email addresses for about 12.2 million users and passwords for 7.6 million accounts. Those are not one figure with a qualifier. Address exposure produces targeted messages that are more convincing because the sender knows where you hold an account. Password exposure produces attempts elsewhere, because the value of a password is rarely the account it came from — it is every other service where the same one was used.

Breach coverage compresses. A headline reports the larger number and describes the incident by its size, which is a reasonable way to convey scale and a poor way to convey what anybody should do.

The two categories here have different half-lives and different remedies. Four and a half million people had an address exposed and nothing else; seven and a half million had both. The advice for those groups is not the same, and neither is the urgency.

Why a password matters after it is changed

Changing it at the breached service takes a minute and closes the smallest part of the problem. What persists is that the string is now on a list, and lists are used against services that were never breached, by people testing whether the same password opens a bank, an email account, or a retailer.

Which is why one organisation's incident becomes a hundred organisations' problem, none of whom did anything wrong and none of whom will appear in the reporting. The mechanism is entirely the reuse, and the reuse is entirely rational from where the person is standing: nobody can hold two hundred distinct strings in their head.

The address is not harmless either

An address paired with a known service relationship is what makes an approach credible. A message that opens by naming your telecoms provider, correctly, clears the first check most people apply — and it clears it because the fact is true.

That is the durable damage. Passwords can be changed and eventually will be. The knowledge that a specific person holds an account with a specific company does not expire, and it improves every approach made to that person for years.

What actually helps, in order

Unique passwords, which requires a manager, because the requirement is impossible otherwise. Then a second factor that is not a code sent by message, for the reason May's relay campaigns demonstrated. Then, for the address exposure, nothing technical at all: the expectation that approaches will be well informed, and the habit of verifying through a channel the message did not supply.

That last one is the only defence available against a fact that cannot be recalled, and it is the reason breach notifications should say which category a person is in. Most do not, which leaves millions of people applying the wrong remedy to the wrong exposure.