Skip to main content
Emerging ThreatsData Breaches

Sakura Internet Breach Exposes 1.36 Million Accounts

Rows of computer servers and networking equipment in a brightly-lit data center with a blurred laptop screen in the…

1,360,563 member accounts — that is the figure Sakura Internet reported as potentially compromised after attackers gained access to its sales management system, the company announced in an update to an earlier notice.

How the incident was discovered and the initial timeline

Sakura Internet says hackers accessed its IT system on August 9. The company discovered that intrusion while investigating a separate breach of its Sakura Rental Server service. In that earlier incident, unauthorized logins were observed on 583 accounts and customer-facing systems were accessed. Sakura’s update expanded the scope of concern when forensic work turned up access to the sales management system where contract and membership information is stored.

What was accessed, and what may — or may not — have been taken

The company’s investigation to date indicates as many as 1,360,563 member accounts were potentially compromised, though Sakura has said the exact number remains to be determined and that no data exfiltration has been confirmed. Sakura also stated that the sales management system does not store credit card information and that stored passwords are hashed and “should be hard to decipher even if stolen.”

Malware, credential abuse, and remediation steps reported

In the Rental Server incident, Sakura reported that attackers installed malware onto its systems; the company said it invalidated all abused credentials and removed the malware. The update did not identify the type of malware discovered, and Sakura did not report any operational or service disruptions. BleepingComputer reported it could not find a ransomware or data-extortion actor publicly claiming the attack and that its request for additional information from Sakura had not received a response at the time of its article.

Sakura Internet’s strategic position and why this matters to Japan’s Government Cloud program

Sakura Internet is a major Japanese digital infrastructure provider offering web hosting, VPS, public cloud, data-center, and GPU computing services. The company has been selected as a domestic provider for Japan’s Government Cloud program, a role the firm’s announcement framed as reducing dependence on foreign hyperscalers. That selection makes Sakura a strategic domestic supplier; the company itself alerted the “relevant authorities” after the breach and said it is individually notifying affected customers about exposed data.

What this means for technologists, policymakers, and customers

  • Technologists and security teams: The company’s account of invalidating “abused credentials” and the Blue Report 2026 observation cited in the article — that “once attackers are using valid credentials, prevention drops sharply” — underline the challenge of credential-based intrusions. Teams will be watching for credential theft, reuse, and follow-on access, and will take note that hashed passwords and the absence of stored card data were specifically reported by Sakura.
  • Policymakers and regulators: Because Sakura is a selected domestic provider for the Government Cloud program, regulators and procurement officials are likely to weigh the incident’s implications for continuity, data residency, and supplier trust. Sakura informed relevant authorities and is notifying customers individually, steps that will inform any regulatory follow-up referenced in public statements.
  • Affected customers and enterprises: Sakura has said it is individually notifying customers whose data may have been exposed. The company’s public claims — no confirmed exfiltration so far, hashed stored passwords, and no stored credit card data on the compromised system — will be central to customers’ risk assessments as the investigation continues.

The facts reported so far leave several concrete questions pending: the precise number of accounts affected, whether forensic work will confirm any exfiltration, the nature of the malware installed in the Rental Server incident, and whether any extortion or ransom claims will surface. Sakura has taken and reported immediate remediation steps — credential invalidation and malware removal — and has notified authorities and impacted customers, but the company’s lack of response to at least one media inquiry and the unresolved technical details mean the story remains active.

Read the original BleepingComputer report: https://www.bleepingcomputer.com/news/security/sakura-internet-hack-exposes-data-of-up-to-136-million-accounts/