Resolved High impact Data breach Checked 1d ago

Sakura Internet breach may expose 1.36 million accounts

Sakura Internet's final investigation found that customer information in its sales management system may have been viewed or obtained. The possible scope is 1,360,563 accounts. Hashed member ID password information may have been viewed for 30 accounts. A separate rental server incident affected 951 accounts, including 368 identified after the initial disclosure. Sakura said the two incidents were not clearly linked and found no clear evidence that data was taken outside the company.

Started
Aug 9, 2026
Latest activity
Sep 10, 2026
Closed out
Sep 10, 2026
Attributed to
Not confirmedNo credible attribution yet
Where
Japan
Sectors
Technology
Scale
One company

Current status

On 2026-09-10, Sakura Internet said its investigation was complete, containment was finished, and it found no clear evidence of data removal or secondary misuse.

Resolved: Services were restored and the incident was closed out.

Impact

The sales management system breach may have exposed customer contact and contract information for 1,360,563 accounts. Hashed member ID password information may have been viewed for 30 accounts. The system also held some initial server passwords for certain rental server and VPS accounts. Sakura said these were separate from the 30 hashed password records. In the separate rental server incident, 951 accounts may have been viewed or obtained, and malware was found on some servers. Sakura found no clear evidence of data removal, account misuse, or other secondary harm.

What to do

If you are a Sakura Internet customer, check for a direct notice from the company and follow its instructions. If Sakura changed a server password for you, log in through the member menu and set a new password. Use a unique password and stay alert for phishing messages that use your contact or contract details. Verify unexpected messages through Sakura's official website or support channels.

Timeline

  1. Sep 10, 2026

    Sakura Internet said its investigation was complete. It reported that containment was finished, found no clear evidence that data was taken outside the company, and confirmed no known account misuse or other secondary harm. The final scope included 1,360,563 sales management system accounts, 30 accounts whose hashed member ID password information may have been viewed, and 951 rental server accounts potentially affected.

    Resolvedsakura.ad.jp
  2. Aug 31, 2026

    Sakura Internet began sending individual notification emails, required under Japan's personal information protection law, to accounts potentially affected by the sales management system breach. The notice told recipients that no clear evidence was found linking that breach to the separate Sakura Rental Server incident. Recipients on social media reported receiving the email even though some had not used the service in over a decade.

    Containeditmedia.co.jp
  3. Aug 26, 2026

    Sakura Internet updated its notice to add a dedicated phone contact line, saying it has invalidated the credentials used in the intrusion, removed malware, strengthened monitoring, and continues a forensic investigation with outside specialists.

    Containedsakura.ad.jp
  4. Aug 20, 2026

    Sakura Internet disclosed that up to 1.36 million customer accounts may be within the scope of the breach, with passwords hashed and salted and no confirmed data exfiltration.

    Emergingbitdefender.com
  5. Aug 19, 2026

    Investigating the rental server breach, Sakura Internet found a separate unauthorized access to its sales management system that occurred before the August 9 detection date, and confirmed hashed passwords were accessible to the intruder for some customers in that system; no external data transfer has been confirmed.

    Activesakura.ad.jp
  6. Aug 17, 2026

    Sakura Internet disclosed unauthorized logins to 583 customer accounts on its Sakura Rental Server service; the attacker reached areas that could access customer accounts and malware was found installed, with some personal data possibly viewed or obtained.

    Activesakura.ad.jp
  7. Aug 9, 2026

    Sakura Internet discovered unauthorized access to its sales management system.

    Emergingscworld.com

Sources

Related reports