I Received an @nifty Password Change Request Email and Considered the Possibility of a Scam
I usually read my @nifty emails using the Mail app on my iPhone, but one day I noticed that a garbled email had arrived from @nifty.
The timestamp showed 10:13 a.m. on June 24, 2026. Although the subject line was partially readable--"【重要】メールパスワード漏えいの..." --the moment I tapped it, the entire message body appeared completely garbled and unreadable.
From the visible part of the subject, I assumed it was related to the password leak incident that had been reported in the news the previous night. I considered checking the message through @nifty Webmail on my iPhone, but logging in through the browser felt troublesome. So later that night, before going to bed, I logged into @nifty Webmail from my PC in the next room to check the contents of the garbled email.
When I reached the @nifty Webmail login screen, I was surprised.

A notice appeared saying, "From 6/24 11:40, login notification emails have been suspended due to heavy load." (This screenshot was taken around 23:17 on June 24, 2026.)
It seemed that many @nifty users, alarmed by the password leak news, rushed to the login page they normally never visit, causing unexpected load on the mail servers. For users like me who mainly use @nifty email through smartphone or PC mail apps, visiting the @nifty website has become rare.
After logging into @nifty Webmail, I was finally able to read the email that had appeared garbled on my iPhone.

題名:【重要】メールパスワード漏えいの可能性に伴う変更手続きのお願い
差出人:ニフティ株式会社
返信先:auto-reply@nifty.com
宛先:■■■■■■■■■■■■@nifty.com
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
【重要】メールパスワード漏えいの可能性に伴う変更手続きのお願い
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
平素より@nifty(アット・ニフティ)をご利用いただき誠にありがとうございます。
このたび、お客様がご利用の「@niftyメール」において、外部からの不正アクセスに よりメールアドレスおよびメールパスワードが漏えいした可能性のあることが判明いたしました。
お客様には多大なるご迷惑をおかけしましたことを、心よりお詫び申し上げます。
二次被害を防止し、お客様のメールアカウントの安全を確保するため、大変お手数ですが、まずは以下期日までにメールパスワードの変更手続きをお願いいたします。
───────────────────────────────────
■期日までに必ずご対応いただきたいこと
ご対応内容:@niftyメールのパスワード変更
お手続き期日:2026年6月25日(木) 23:59 まで
【お手続き方法】
対象メールアドレスの確認および変更方法については、以下の会員サポートページをご確認ください。
⇒ https://support.nifty.com/topics/2026/06232410
※@nifty公式ホームページからもご案内しております。
※メールパスワードとログインパスワードを同じ文字列に設定されている場合などは、
ログインパスワードも合わせて変更することをお勧めいたします。
■期日までにご対応いただけなかった場合の影響
上記期日までに変更が確認できない場合、メールアドレス保護のため、システム側で順次「メールパスワードを無効化」いたします。
無効化された場合、それまでのパスワードではメールの送受信ができなくなりますのでご注意ください。
制限がかかった場合も、上記URLまたは公式サイトよりパスワードの変更を実施いただくことで、再度ご利用可能となります。
■ 経緯と詳細についてのご報告
【発生した事象】
当社メールサービスの基盤システム(提供元:KDDI株式会社)の脆弱性を悪用した不正アクセスが発生し、お客様のメールアドレスおよびメールパスワードが第三者に漏えいした可能性がございます。
【現在の対応状況】
提供元において該当箇所の技術的な防御措置はすでに完了しております。現在は影響範囲の特定に向けて調査を継続しておりますが、二次被害などの潜在的なリスクを排除するための必須措置として、今回のパスワード変更をお願いする運びとなりました。
■(参考)2つのパスワードの使い分けについて
Webメールへのログインには「ログインパスワード」を利用します。今回の変更対象である「メールパスワード」とは異なりますのでご注意ください。
【各種パスワードの違いについて詳しくはこちら】
⇒https://support.nifty.com/support/member/idpass/id_username.htm
───────────────────────────────────
お客様には多大なるご迷惑とご負担をおかけし誠に恐縮ではございますが、お客様のメールアドレスの安全を確保するため、何卒期日までの変更手続きにご協力を賜りますようお願い申し上げます。
本件に関する詳細および最新情報は、@nifty公式サイトのトップページにも掲載しております。
なお、本件に関してご不安な点やご不明な点がございましたら、下記のお問い合わせ窓口までご連絡をお願いいたします。
<@nifty特設ダイヤル>
・電話番号 0120-985-275
(受付時間 10時00分~18時00分/毎日)
English summary of the quoted email:
This message from Nifty Corporation explains that unauthorized access to the email system (provided by KDDI) may have resulted in the leak of users' email addresses and email passwords. As a precaution, all affected users are asked to change their email password by June 25, 2026, at 23:59. If the password is not changed by the deadline, the current email password will be disabled for security reasons. The email also clarifies that the "email password" is different from the "login password" used for Webmail. A dedicated support line is provided for users who have questions or concerns.
I had already changed my email password the previous night, so I assumed I could safely ignore this message titled "【重要】メールパスワード漏えいの可能性に伴う変更手続きのお願い". It would have been helpful if the email had included a line such as "This message is also sent to users who have already changed their password." For a moment, I wondered whether I needed to change my password again.
More than that, what concerned me was whether this message could be a phishing email. If I hadn't known about the password leak incident from the news, I might have dismissed it as "another scam email" and deleted it without reading.
Since the email appeared garbled on my iPhone, if I hadn't known about the leak, I probably would have assumed it was a scam and deleted it immediately.
Considering how phishing scams work--where users are tricked into clicking fake links and entering their username and password on a fraudulent website--it worries me that malicious actors might impersonate Nifty Corporation, send fake emails, and lure @nifty users to phishing sites. Someone aware of the password leak might unknowingly enter their @nifty ID and password into a fake site.
I really hope no one gets tricked.