Japanese telecom operator KDDI confirmed that attackers had exploited a zero-day vulnerability in third-party software to break into a shared email platform it runs for internet service providers. The intrusion happened on May 16, 2026, and KDDI did not detect it until June 17. By the time the company finished its assessment, the numbers were stark: roughly 12.23 million email addresses and 7.61 million passwords exposed across six ISPs, including STNet, JCOM, Chubu Telecommunications, NIFTY, and BIGLOBE. A month later, Japan’s Council of Anti-Phishing published its June report and drew a direct line from that breach to a surge in phishing it had just watched unfold, one that no amount of DMARC enforcement alone could have stopped.
A Breach in Shared Infrastructure, Not a Single Company
KDDI did not run consumer email accounts itself. It operated the underlying platform that several of Japan’s largest ISPs relied on to provide email service to their own customers, which is exactly why one vulnerability in one piece of third-party software turned into a multi-provider incident instead of a contained one. When shared infrastructure fails, the blast radius belongs to everyone who built on top of it, not just the operator whose name is on the breach notice. KDDI reported the incident to Japan’s Ministry of Internal Affairs and Communications, forced password resets across the affected ISPs, and completed a forensic audit on June 23 confirming the vulnerability had been closed.
The Surge the Council Was Watching Line Up
Japan’s Council of Anti-Phishing published its monthly report for June 2026 on July 16, logging 72,370 phishing reports and 42,241 unique phishing URLs for the month. The report’s headline finding was a sharp rise, starting around June 10, in phishing sent through genuinely compromised email accounts at domestic ISPs, arriving just weeks after credentials from the KDDI-linked platforms had been exposed. The council’s conclusion was blunt: leaked ISP mail credentials do not stay contained to the mail account they were stolen from. They get reused across banking, retail, and other services, and the accounts themselves become launch points for further phishing sent from addresses with a real, unblemished sending history.
Why This Is the Phishing DMARC Cannot Catch
DMARC checks whether a message’s sending infrastructure is authorized to use the domain in its From header. When an attacker takes over a real mailbox with a stolen password, that check has nothing to fail. The message goes out through the account’s own legitimate mail server, signs with the account’s own valid DKIM key, and aligns perfectly with SPF and the From domain, because every part of it is genuine except the person typing. This is structurally different from spoofing, where DMARC blocks a forged sender outright, and different even from platform-notification abuse, where a real company’s infrastructure gets tricked into sending on an attacker’s behalf. Here there is no infrastructure to trick. The account itself has been handed over.
Why the Council Reached for DMARC Reject Anyway
It might seem strange to respond to account-takeover phishing by pushing sending domains toward stricter DMARC enforcement, since DMARC cannot see inside a compromised mailbox. But the council’s guidance is aimed at a different, adjacent risk that always follows a credential leak of this size: once attacker groups have working ISP mailbox logins, they use those same domains and login patterns to test spoofing attempts against every business those users interact with. A domain sitting at p=none or p=quarantine gives that follow-on spoofing traffic somewhere to land. Moving to p=reject does not stop the compromised mailbox from sending real phishing under its own real identity, but it does close the door on attackers layering forged lookalike traffic on top of the chaos a breach like this creates, while receiving mail servers are already primed to distrust the affected domains.
BIMI and Passkeys Round Out the Response
The council’s other two recommendations target what DMARC structurally cannot: BIMI gives recipients a verified visual signal for legitimate mail once DMARC enforcement is in place, making it marginally easier to notice when a message lacks that signal even if it technically authenticates. Passkeys attack the root cause directly, since phishing-resistant authentication makes a stolen password worth nothing on its own, exactly the credential type this breach put into circulation by the millions.
What This Means Beyond Japan
Treat any large-scale credential exposure, yours or a vendor’s, as a phishing-readiness event, not just a notification obligation. If a platform your organization or its users rely on discloses a breach, assume compromised accounts will be used to send convincing, fully-authenticated phishing within weeks.
Push toward DMARC reject before an incident forces the timeline. Enforcement in place ahead of a breach means one less thing to react to when forged traffic starts probing your domain’s reputation in the aftermath.
Adopt phishing-resistant authentication wherever your organization can. Passwords leaked in bulk are a certainty at this point in the industry’s history; the response that actually holds is removing the password’s value entirely.
Monitor for account-takeover patterns, not just authentication failures. A spike in DMARC pass-rate combined with unusual sending behavior from a known-good source is often the only visible signal that a real account has been hijacked.
The Takeaway
The KDDI breach and the phishing surge that followed it are a reminder that DMARC enforcement and account security solve different problems that happen to sit right next to each other. A stolen password turns a legitimate mailbox into a fully-authenticated phishing weapon that DMARC will wave through every time. The right response is not to abandon DMARC enforcement because it cannot see this threat. It is to keep tightening it for the threats it can stop, so that when a breach like this one inevitably happens somewhere in your supply chain, forged traffic riding on the confusion is not one more problem you have to fight.
Excello Mail keeps your domain at full DMARC enforcement and gives you clear visibility into every source claiming to send on your behalf, so that when a breach happens somewhere else in the ecosystem, your own domain is not an easy target for the forged traffic that follows. Sign up for free to Excello Mail and get your domain to reject before you need it to be.