I Changed My @nifty Email Password After the Security Breach Report

On Tuesday, June 23, 2026, KDDI Corporation published a press release titled "Unauthorized Access to Email Systems for ISP Providers." Major news sites immediately reported it as a serious incident, and on Yahoo! JAPAN--which I check almost every day--the news appeared prominently on the "Top" tab of the front page.

The first thing that came to mind when I saw "KDDI's email system" was the old DION email address I personally use. However, after reading the details carefully, I learned that DION addresses were not affected, which was a relief... but only for a moment. It turned out that another email address I use was included in the affected services.

The email services provided by STNet's Pikara and Nifty Corporation's @nifty email were both affected.

I was extremely concerned, but since I was at work, I had to wait until after I returned home around 9 p.m. to discuss the situation with my wife.

According to her, when we signed up for STNet's Pikara fiber-optic service, a Pikara email address was issued, and she occasionally uses it. As for the @nifty email address, I have been using it almost every day for more than 20 years--it is very important to me.

We decided that my wife would handle the Pikara email password issue, while I would take care of the @nifty email password after dinner.

When I opened the @nifty homepage, I saw a link at the top titled "Unauthorized Access to Our Email Service and How to Respond." I clicked on it.

The linked page explained how to check whether my email password had been leaked and described the measures Nifty Corporation would take. Among the information provided, the following two statements concerned me the most:

Because the "email password" for @nifty mail was targeted in this unauthorized login incident, we kindly ask affected users to complete the following steps by June 25, 2026 (Thu) 23:59.
If we cannot confirm a password change by the deadline, we will begin disabling the current email password to protect the security of your account.

In other words, if my email password had been leaked, I would need to change it myself before 23:59 on June 25, 2026 (before June 26 begins). If I failed to do so, Nifty would forcibly disable my password after midnight on June 26, making the email account unusable.

This is understandable from a security perspective, but I can easily imagine the Nifty support center being flooded with calls from users saying, "I can't access my email anymore." I feel sorry for both the users and the support staff.

On the same page, there was a link labeled "Change Email Password." Clicking it brought me to the following screen:

@nifty login screen (June 23, 2026)

[Important] Request to Change @nifty Email Password (Affected Users Only)
Due to unauthorized access, some users are required to change their email password by June 25 (Thu). Accounts that do not complete the change by the deadline will have their current password disabled.
Please check below to confirm whether your account is affected.
⇒ Check Affected Accounts and Details

Clicking "Check Affected Accounts and Details" simply returned me to the earlier page, so instead I logged in directly using my @nifty ID and password.

@nifty password check screen (June 23, 2026)

A page titled "Password Change Eligibility Check" appeared. (For security reasons, the email address shown in the screenshot on this blog is blacked out.)

@nifty Email Basic Information
■■■■■■■■@nifty.com
Last Password Change: 2003/09/05 20:11:18

This address is subject to mandatory password change. We kindly ask you to complete the password update procedure.

Proceed to Password Change →

It appeared that my @nifty email account was indeed affected, so changing the password was mandatory. (Even if it hadn't been affected, I would have changed it anyway because it felt unsafe.)

Seeing that my last password change was on "2003/09/05 20:11:18" made me feel nostalgic, but also made me realize that going nearly 23 years without changing a password is not ideal from a security standpoint.

My wife said, "You're finally saying goodbye to a password you've used for so long," which made me feel sentimental. I know it's not good to use the same password for decades, but still--changing a password I've used for 23 years feels a bit sad. In a way, it's impressive that @nifty's system withstood unauthorized access for so long. If only the malicious actor hadn't attacked KDDI's system, none of this would have happened. People who cause such incidents really need to stop.

@nifty login and email password change screen (June 23, 2026)

Please set your new password according to the following rules:

Use 6-24 half-width characters. Uppercase and lowercase letters are distinguished.
Symbols may be used. Avoid easily guessable information such as names or birthdates.
[Allowed Characters]
A-Z a-z
0-9
Symbols: " # $ % & ' ( ) * + , - . / : ; < = > ? @ [ ] ^ _ ` { | } ~ !
※ Cannot be the same as your @nifty ID.
※ Some symbols may not work with certain modem devices on always-on connections.
[Symbols That May Not Work] % ? " + @ \

I changed both my login password and email password on this screen.

@nifty password change completion screen

Change Completed
Your password change request has been processed.
・Login Password
・Email Password

It may take some time for the new email password to take effect.
Please wait for a moment.

Clicking "Check Password Change Eligibility" again brought me to the updated confirmation screen:

@nifty password change confirmation screen (after change)

@nifty Email Basic Information
■■■■■■■■@nifty.com
Last Password Change: 2026/06/23 23:57:25

This address has already completed the password change.

With this, I successfully changed both my @nifty email password and my @nifty login password. I feel relieved for now.

前へ

@niftyでメールパスワード漏洩報道。対象者だったので変更した

次へ

@niftyのパスワード変更要請メールを受信し、詐欺の可能性を考えた