Enforcement record

Directive disclosure naming KDDI株式会社

KDDI株式会社 (Telecommunications Business Act)

This page records one action from a Japanese government disclosure, including the published name, governing law, authority, action details, and official source.

Telecommunications Business ActMinistry of Internal Affairs and CommunicationsGovernment disclosure29 July 2026

Action type

Directive

Law

Telecommunications Business Act

Authority

Ministry of Internal Affairs and Communications

Action date

29 July 2026

Current page: Enforcement record

This screen focuses on one disclosed action: the published name, governing law, authority, facts, source status, and review evidence.

Free report

Save the disclosure record naming KDDI株式会社

Includes the published name, regulator, governing law, source links, archive status, and reviewer note fields for internal due-diligence files.

For developers: JSON integration details

You do not need this for normal browsing. Use it only when integrating this enforcement record into an internal tool or AI workflow.

/api/v1/enforcements?company=KDDI%E6%A0%AA%E5%BC%8F%E4%BC%9A%E7%A4%BE&limit=10

Action summary

Company
KDDI株式会社Japanese only
Original: KDDI株式会社
Governing law
Telecommunications Business Act
電気通信事業法
Action type
Directive
指示
Action date
29 July 2026
Issuing authority
Ministry of Internal Affairs and Communications
総務省
Industry context
通信事業
Affected consumers
7,620,000

Violation

Machine-translated summary — verify against original

On July 29, 2026, the Ministry of Internal Affairs and Communications issued a directive to KDDI Corporation under the Telecommunications Business Act. The company experienced a data breach caused by unauthorized external access to its email systems provided to multiple internet service providers. As a result, email addresses and login passwords were leaked, allowing a third party to access about 7.62 million users' email inboxes. The ministry instructed KDDI to strengthen the protection of communication secrets, implement necessary measures to prevent recurrence, and report on the status of these measures.

Show original Japanese text

KDDI株式会社が複数のインターネットサービスプロバイダ向けに提供するメールシステムにおいて、外部からの不正アクセスに起因し、ユーザーのメールアドレスやメールシステムへログインするためのパスワード等のメール関連情報が漏えいし、パスワードを窃取した第三者において、約762万人のユーザーのメールボックス内の情報が閲覧可能な事態となった。

Business location and permit details

Representative
松田 浩路

These fields are extracted from the original Japanese disclosure or linked overview pages when available.

Compliance context

Medium

A regulator issued a directive requiring specified action.

Telecommunications law governing telecommunications services and related user protection obligations.

Verify the required action and whether the company has disclosed remediation or completion.

This context is an operational aid for review workflows, not a credit opinion or legal conclusion.

Evidence pack

Original Ministry of Internal Affairs and Communications source (Japanese)
Extracted at
2026-07-29T12:03:25.106+00:00
Evidence checked
2026-07-29T12:03:25.035+00:00
Archive captured
Not archived
Show audit JSON
{
  "record": {
    "id": "19243302-02d5-4d94-aeaf-579db4d3c9a8",
    "url": "https://regbase.jp/en/enforcement/denki-tsushinho-kddi-20260729",
    "company_name_original": "KDDI株式会社",
    "company_name_registry": null,
    "corporate_number": null,
    "law": {
      "ja": "電気通信事業法",
      "en": "Telecommunications Business Act"
    },
    "action_type": {
      "ja": "指示",
      "en": "Directive"
    },
    "authority": {
      "ja": "総務省",
      "en": "Ministry of Internal Affairs and Communications"
    }
  },
  "entity_match": {
    "status": "unresolved",
    "confidence": 88,
    "method": "nta_historical_strict_name_nationally_unique",
    "method_label": "nta_historical_strict_name_nationally_unique",
    "notes": "有力な法人候補がありますが、自動確定に必要な独立証拠が不足しています(nta_historical_strict_name_nationally_unique)。"
  },
  "review": {
    "status": "needs_review",
    "label": "Needs review"
  },
  "compliance_context": {
    "severity": "Medium",
    "actionMeaning": "A regulator issued a directive requiring specified action.",
    "practicalNote": "Verify the required action and whether the company has disclosed remediation or completion.",
    "lawContext": "Telecommunications law governing telecommunications services and related user protection obligations."
  },
  "evidence": {
    "recordUrl": "https://regbase.jp/en/enforcement/denki-tsushinho-kddi-20260729",
    "officialSourceUrl": "https://www.soumu.go.jp/menu_news/s-news/01kiban18_01000285.html",
    "officialDocumentUrl": null,
    "archiveUrl": null,
    "archivedSourceUrl": null,
    "archiveCapturedAt": null,
    "extractedAt": "2026-07-29T12:03:25.106+00:00",
    "translatedAt": "2026-07-29T12:10:52.901+00:00",
    "evidenceCheckedAt": "2026-07-29T12:03:25.035+00:00",
    "generatedAt": "2026-07-29T14:12:06.838Z"
  },
  "limitations": [
    "RegBase aggregates public Japanese government disclosures and does not provide a credit opinion.",
    "English summaries are provided for reference. The original Japanese source is authoritative.",
    "Possible or unresolved entity matches should be manually verified before use in a decision."
  ]
}

The original Japanese disclosure is the authoritative record. Use possible or unresolved matches only as leads for manual review.

About this recordAggregated and translated from public Japanese government disclosures. The English text is for reference only — authoritative content is the linked Japanese source.