Sakura Internet Breach Exposes 1.36 Million Customer Accounts

Published August 21, 2026

Sakura Internet, a major Japanese cloud hosting company, says attackers broke into its customer management system and may have exposed personal and contract data for up to 1.36 million customer accounts. Passwords were stored hashed and salted, and there is no confirmed proof the data was actually stolen.

Report priority
Medium
Involves
Sakura Internet

What is known

Sakura Internet found the intrusion while investigating a separate incident on its Rental Server service, and traced it to attackers who logged into 583 accounts without authorization, reached systems holding customer data, and planted malware on company servers before staff removed it.

What to do

Watch for a direct notice or update on Sakura Internet's official security advisory page, and change your account password as a precaution even though stored passwords were salted and hashed rather than plaintext.

Reported details

Attackers log into 583 Sakura Internet customer accounts without authorization. They use that access to reach the customer-facing systems that hold contract and personal data, and they plant malware on Sakura Internet's own servers. Sakura Internet's security team discovers the malware while looking into a separate problem on its Rental Server service, removes it, and resets every credential that could have been exposed.

Attackers gained unauthorized access to Sakura Internet's customer management system, which holds contract and personal or corporate data for about 1.36 million accounts. The company confirmed 583 accounts had unauthorized logins, that attackers reached customer-facing systems, and that malware was installed on Sakura Internet's own infrastructure, discovered while investigating a separate incident on the Sakura Rental Server service. The malware was removed and potentially exposed credentials were rotated.

Passwords were never stored in plaintext, only as salted hashes, which limits the practical risk of direct account takeover even if the data was taken. No group has claimed responsibility, Sakura Internet says the incident is unrelated to ransomware with no ransom demand made, and no confirmed data exfiltration has been established.