Sakura Internet breach may expose 1.36 million accounts
Sakura Internet's final investigation found that customer information in its sales management system may have been viewed or obtained. The possible scope is 1,360,563 accounts. Hashed member ID password information may have been viewed for 30 accounts. A separate rental server incident affected 951 accounts, including 368 identified after the initial disclosure. Sakura said the two incidents were not clearly linked and found no clear evidence that data was taken outside the company.
- Started
- Aug 9, 2026
- Latest activity
- Sep 10, 2026
- Closed out
- Sep 10, 2026
- Attributed to
- Not confirmedNo credible attribution yet
- Where
- Japan
- Sectors
- Technology
- Scale
- One company
Current status
On 2026-09-10, Sakura Internet said its investigation was complete, containment was finished, and it found no clear evidence of data removal or secondary misuse.
Resolved: Services were restored and the incident was closed out.
Impact
The sales management system breach may have exposed customer contact and contract information for 1,360,563 accounts. Hashed member ID password information may have been viewed for 30 accounts. The system also held some initial server passwords for certain rental server and VPS accounts. Sakura said these were separate from the 30 hashed password records. In the separate rental server incident, 951 accounts may have been viewed or obtained, and malware was found on some servers. Sakura found no clear evidence of data removal, account misuse, or other secondary harm.
What to do
If you are a Sakura Internet customer, check for a direct notice from the company and follow its instructions. If Sakura changed a server password for you, log in through the member menu and set a new password. Use a unique password and stay alert for phishing messages that use your contact or contract details. Verify unexpected messages through Sakura's official website or support channels.
Timeline
-
Sep 10, 2026
Sakura Internet said its investigation was complete. It reported that containment was finished, found no clear evidence that data was taken outside the company, and confirmed no known account misuse or other secondary harm. The final scope included 1,360,563 sales management system accounts, 30 accounts whose hashed member ID password information may have been viewed, and 951 rental server accounts potentially affected.
Resolvedsakura.ad.jp -
Aug 31, 2026
Sakura Internet began sending individual notification emails, required under Japan's personal information protection law, to accounts potentially affected by the sales management system breach. The notice told recipients that no clear evidence was found linking that breach to the separate Sakura Rental Server incident. Recipients on social media reported receiving the email even though some had not used the service in over a decade.
Containeditmedia.co.jp -
Aug 26, 2026
Sakura Internet updated its notice to add a dedicated phone contact line, saying it has invalidated the credentials used in the intrusion, removed malware, strengthened monitoring, and continues a forensic investigation with outside specialists.
Containedsakura.ad.jp -
Aug 20, 2026
Sakura Internet disclosed that up to 1.36 million customer accounts may be within the scope of the breach, with passwords hashed and salted and no confirmed data exfiltration.
Emergingbitdefender.com -
Aug 19, 2026
Investigating the rental server breach, Sakura Internet found a separate unauthorized access to its sales management system that occurred before the August 9 detection date, and confirmed hashed passwords were accessible to the intruder for some customers in that system; no external data transfer has been confirmed.
Activesakura.ad.jp -
Aug 17, 2026
Sakura Internet disclosed unauthorized logins to 583 customer accounts on its Sakura Rental Server service; the attacker reached areas that could access customer accounts and malware was found installed, with some personal data possibly viewed or obtained.
Activesakura.ad.jp -
Aug 9, 2026
Sources
- Sakura Internet reports potential compromise of over 1.3 million customer accounts SC World Aug 20, 2026
- Sakura Internet Breach Exposes 1.36 Million Customer Accounts SecurityOnline Aug 21, 2026
- Sakura Internet hack may affect 1.36 million accounts Bitdefender Aug 20, 2026
- 当社レンタルサーバーサービスの一部環境に対する不正なアクセスについて sakura.ad.jp Aug 17, 2026
- 当社システムへの不正アクセスに関するお知らせ(第二報) sakura.ad.jp Aug 26, 2026
- 「当選した」自虐投稿も……さくら136万件漏えい可能性、対象者へ通知メール続々 ITmedia NEWS Sep 1, 2026
- さくらインターネット襲った不正アクセス、わずか2日で「583→136万アカウント」に影響拡大 Sep 1, 2026
- Investigation results and measures to prevent recurrence concerning unauthorized access to company systems, third report Sakura Internet Sep 10, 2026
Related reports
- Sakura Internet Breach Exposes 1.36 Million Customer Accounts Aug 21, 2026
- Sakura Internet customer data breach in Japan Aug 20, 2026