Japan’s Council of Anti-Phishing published its monthly report for June 2026 on 16 July, recording 72,370 phishing reports and 42,241 unique phishing URLs for the month. The headline finding is a sudden surge, from around 10 June onward, in phishing sent through compromised email accounts at domestic ISPs. The council warned businesses that credentials leaked from ISP mail systems can be reused across other services, and urged operators to surface authentication failures more clearly, plan migration to DMARC reject policies, consider BIMI, and roll out phishing-resistant MFA such as passkeys. The backdrop is a major intrusion into a shared KDDI mail platform serving several of Japan’s largest ISPs.
The numbers
Total phishing reports fell sharply in June, down 53,691 from May, while unique phishing URLs rose by 1,329. Ninety-eight brands were abused, with Amazon impersonation the most common at around 24 per cent, followed by VISA at roughly 11.8 per cent, then Apple, Sumitomo Mitsui Card, and Docomo. The top five brands accounted for around 55 per cent of all reports.
The sending infrastructure data will interest deliverability practitioners most. Around 75.3 per cent of phishing mail observed at the council’s monitoring addresses originated from IP addresses in the United States, with Singapore, China, and Hong Kong following, and the council flagged surging abuse of US cloud services. It also made a pointed observation about reverse DNS. Abusive senders favour services where a default reverse DNS name exists, or where reverse DNS can be changed easily, because passing forward-confirmed reverse DNS checks helps their mail reach even strictly filtered mailbox providers. Reverse DNS hygiene, in other words, is being gamed as a deliverability asset by attackers.
Hijacked mailboxes and the KDDI platform breach
The surge in phishing from compromised domestic ISP accounts did not happen in a vacuum. On 6 July, KDDI updated its disclosure of an intrusion into an email system it provides to ISP partners, confirming that around 12.23 million email addresses and 7.61 million passwords were accessed. The attacker exploited a previously unknown vulnerability in third-party software embedded in the platform, with access beginning on 16 May and detection and blocking on 17 June. Affected services span BIGLOBE, J:COM, NIFTY, STNet, Chubu Telecommunications, and KDDI Web Communications, and BIGLOBE and J:COM issued their own updates on 6 July. Forced password resets followed across the affected user base.
Phishing sent from a genuinely compromised mailbox is the hardest kind for the receiving side to stop. It comes from real infrastructure, from a real account, and it authenticates. SPF, DKIM, and DMARC all pass, because the mail really is from where it claims to be from. That is the same structural problem we examined when scam mail rode legitimate Xero infrastructure through every authentication check, and it is why the council’s response reaches beyond authentication into identity assurance and MFA.
The policy push
Alongside the compromised-account warning, the council highlighted continued spoofing of .go.jp government domains and other Japanese domains where DMARC is absent or sits at p=none. Its 2026 guidelines already recommend a reject policy. The persistence of p=none among high-trust domains is a familiar story. We reported the same weakness at Ireland’s National Treasury Management Agency after a €5 million phishing loss, and the broader point, that adopting authentication standards without enforcement leaves organisations exposed, has been made repeatedly across markets.
The passkey recommendation matters too. Credential theft from mail systems is the raw material for the account compromise that produces authenticated phishing in the first place. Phishing-resistant MFA attacks the problem at its source, a point we also made in our analysis of the attack email authentication cannot see.
Why this matters beyond Japan
This is one of the clearest recent regional signals that deliverability and security are now inseparable disciplines. A national anti-phishing body is telling brands, in one breath, that weak DMARC policies, poor identity signalling, and insufficient MFA create phishing exposure and inbox trust problems together. For international senders, the practical reading is that DMARC at reject, BIMI, reverse DNS hygiene, strict alignment, and passkey rollout are no longer optional trust enhancements. In markets where mailbox compromise spills into phishing at scale, they are part of brand protection, complaint reduction, and long-term inbox placement.








