Sakura Internet customer data breach in Japan

Published August 20, 2026

Sakura Internet, a major Japanese cloud and data center company, says attackers broke into its sales management system. The intrusion may have exposed contract and membership details for as many as 1,360,563 customer accounts.

Report priority
Medium
Victim
Sakura Internet

What is known

Attackers got into an internal sales management system that stores customer contract and membership records, and Sakura Internet found this breach while investigating a separate, smaller break-in on its rental server service.

What to do

Sakura Internet says no credit card numbers were stored in the breached system and customer passwords were hashed, and there is no confirmed evidence data was actually stolen, so wait for the company's direct notification and any guidance it sends before taking action.

Reported details

Sakura Internet investigates a smaller security problem on its rental server service. During that investigation, staff discover that attackers had also gotten into a separate sales management system holding customer contract records. The company estimates the intruders may have been able to view membership and contract details for over 1.3 million accounts, though it has not confirmed any data was actually copied out.

Sakura Internet disclosed that its sales management system, which holds customer contract and membership data, was accessed by an unauthorized party. The company discovered this while investigating a separate, less severe incident on its rental server service. It estimates up to 1,360,563 accounts could be affected.

Credit card data is not stored in the compromised system, and passwords were hashed. No exfiltration has been confirmed, no operational disruption occurred, and no threat actor has claimed responsibility. Sakura Internet has notified Japanese authorities and is contacting affected customers directly.