[News] KDDI Could Leak Email and Others

economy

KDDI announced that unauthorized access to ISP email systems may have resulted in the leakage of up to 14.22 million email addresses and passwords. Behind this is a massive accounting misconduct issue at a subsidiary, putting the entire group’s governance and security system under strict scrutiny.

The largest outflow ever and its impact

On June 23, 2026, KDDI announced that its email system for Internet Service Providers (ISPs) had been compromised, potentially causing up to 14.22 million email addresses and passwords to be leaked externally. The eligible email services include Nifty’s “@nifty Mail,” Biglobe’s “BIGLOBE Mail,” and JCOM’s “J:COM NET,” totaling six companies. The fact that this number includes not only current accounts but also users who have already canceled and dormant accounts that have not been used for a certain period underscores the seriousness of the situation. Compared to the “DION” customer information leak incident in 2006, which resulted in the leak of about 4 million pieces of information, the current figure of 14.22 million cases could be one of the largest in Japan. KDDI claims to have completed system modifications and technical defense measures, but to prevent secondary damage caused by illegally obtained information, it strongly urges affected users to change their passwords promptly. ISPs have also set up dedicated contact points to raise awareness among individual and corporate users.

Attack Methods Exploiting Vulnerabilities in Third-Party Software

This unauthorized access was discovered on June 17, 2026. According to KDDI’s investigation, the cause was the exploitation of a vulnerability in “third-party software” used in the email system provided by the company to ISPs. Attackers exploited flaws in this system and are believed to have illegally obtained credentials linked to mailboxes. On the day the anomaly was confirmed, KDDI carried out system modifications to prevent further damage, identified the suspected areas, and implemented defensive measures. Cyberattack methods are becoming increasingly sophisticated year by year, and while attacks targeting unknown software vulnerabilities are difficult to defend against, it is a serious fact that such a large-scale impact has occurred on KDDI’s foundation, which is the core of its communication infrastructure. Although some leaked passwords were hashed or encrypted, there is no guarantee that all data will be fully protected, making it crucial to be vigilant against secondary damage such as phishing emails and unauthorized logins to other services.

[Management and Governance Crisis] The Impact of Overlapping Inappropriate Accounting Issues

The full picture of a virtual circular transaction worth 246.1 billion yen

Alongside the information leak incident, the KDDI Group is also shaken by a massive accounting misconduct scandal uncovered at a consolidated subsidiary. According to a special investigation committee report published on March 31, 2026, it was revealed that fictitious circular transactions disguised as insubstantial “advertising agency businesses” had been conducted for a long time at the consolidated subsidiaries Big Grove and G-Plan. This fraudulent transaction continued for about seven years, from August 2018 at the latest to December 2025, with the total amount of fraudulent sales recorded reaching an astonishing 246.1 billion yen. Surprisingly, about 99.7% of sales in this business were fictional, and despite no actual advertiser outsourcing of placements, a scheme was built to circulate funds from upstream agencies to downstream agencies and back upstream. All companies involved in this transaction circulated funds by deducting fees, and in reality, it was merely a change of numbers and exploitation of fees.

Structural Flaws in Which Group Finance Was Exploited

The reason mishandling has expanded to this scale and been concealed for a long time lies in the structural issue of KDDI’s abuse of its “group finance” system. After deciding to fully enter the advertising agency business in December 2022, BIGLOBE actively leveraged group finance provided by KDDI to raise funds. The loan limit to the company has increased from 59.9 billion yen in fiscal 2022 to 83 billion yen in fiscal 2025, and this ample cash has functioned as the “source” for fictitious circular transactions. Since each company deducts fees for each transaction, the more the cycle of funds tends to deplete, but the shortfall is compensated by new loans from KDDI, maintaining a “bicycle operation” model. As a result, the total outflow of funds externally has reached approximately 32.9 billion yen. Ironically, the parent company’s efficient fund management system prolonged the fraud and escalated the damage. Please refer to the diagram below.

Figure 1

[Impact on Market and Strategy] Wavering Trust and Business Strategy

Risks of stock price declines and loss of confidence faced by investors

A series of large-scale scandals have severely shaken KDDI’s stock price and investor confidence. When suspicions of misaccounting were first reported in February 2026, the stock price plunged by more than 10% in overnight trading (PTS) trading. KDDI is the leading ‘defensive stock’ that has continued its 22nd consecutive dividend increase, and many individual investors hoping for stable dividends have held it as the core of their portfolios, so the impact is immeasurable. The “lack of management capability,” where fraud had been overlooked for nearly nine years, has led institutional investors to lower their risk assessments, further fueling position adjustment sell-offs. In the market, it is also compared to the case of Nidec (formerly Nidec), which was handled by the same audit firm, and is being discussed as a challenge for Japanese companies as a whole, such as audit limitations and structural flaws in subsidiary governance. Although no major changes have been suggested at this time regarding maintaining the dividend policy, concerns remain in the phase of deteriorating shareholder benefits and curbing share buybacks, which could negatively impact investor returns.

Uncertainty about the “New Satellite Growth Strategy”

KDDI is currently promoting the “New Satellite Growth Strategy” centered on communications to realize “KDDI VISION 2030.” This strategy defined 5G communications as the foundation, finance, energy, and the DX (Digital Transformation) sectors that were the stage for this fraud as growth pillars (Orbit1), aiming for double-digit growth in operating profit. However, the large-scale accounting fraud and significant security incidents occurring one after another at BIGLOBE, a key hub in the DX field, raises significant questions about the execution of strategic strategies. We have extended the period of our medium-term management strategy by one year, aiming to achieve 1.5 times EPS (earnings per share) by the fiscal year ending March 2026. However, cancellations of profits due to fraud and increased security investments to restore trust pose significant barriers to achieving our financial targets. Forward-looking investments such as social AI implementation and digital twin construction will struggle to fully realize their value unless distrust of underlying security and governance is dispelled.

[Future Outlook] The Path to Restoring Trust and Key Points to Watch

Administrative guidance and pursuit of legal responsibility by the Ministry of Internal Affairs and Communications

Authorities are taking an extremely tough stance against the unprecedented risk of information leaks of 14.22 million cases. KDDI has already reported to the Personal Information Protection Commission and the Ministry of Internal Affairs and Communications, but it is certain that administrative guidance will be issued requiring detailed investigation of the cause and measures to prevent recurrence going forward. KDDI has previously received guidance from the Ministry of Internal Affairs and Communications for failing to accurately report on specific related entities, and if improvements in its governance system are judged to be “insufficient,” it could escalate into even stronger business improvement orders. Furthermore, the legal environment surrounding cybersecurity is rapidly tightening, and as seen in China’s revised Cybersecurity Law enforced in January 2026, penalties for delayed or non-compliance in incident reporting are likely to be strengthened not only for companies but also for individuals responsible. KDDI urgently needs to rebuild its compliance framework not only in terms of technical defenses but also from legal and regulatory perspectives at the global level.

Fundamental governance reform and the ability to implement recurrence prevention

The only path left to restore lost trust is fundamental reforms that address the “structural flaws” of group governance. The collapse of internal checks on both the ordering and receiving sides, which allowed inappropriate accounting, and the excessive emphasis on subsidiary autonomy due to ‘laissez-faire’ are issues that need to be corrected as soon as possible. What investors and consumers should pay close attention to going forward is the effectiveness of the recurrence prevention measures presented after the final report at the end of March 2026. It is necessary to implement multi-layered checking functions, such as thorough separation of duties (SoD), ensuring human resource independence within the group, and structural reforms to enhance the independence of audit firms. For companies responsible for the highly public business of telecommunications, security and governance are the very lifelines of business continuity. With the shocking figure of 14.22 million transactions, whether KDDI can achieve “normalization of governance” beyond mere post-processing will determine the company’s long-term corporate value.

[#KDDI #情報漏洩 #不適切会計 #ガバナンス #サイバーセキュリティ #ビッグローブ #株式投資]

コメント

Copied title and URL