Sakura Internet breach spreads to sales system, up to 1.36 million accounts exposed
Japanese cloud and data center provider Sakura Internet said an investigation into a rental-server intrusion uncovered unauthorized access to its sales management system, potentially exposing member and contract data on up to 1,360,563 accounts.
- Victim
- Sakura Internet Inc.
- users
- 1.4M
On 19 August 2026, Sakura Internet, one of Japan's best-known cloud, hosting and data center providers, published a second report on a security incident and said it had found possible unauthorized access to its sales management system. The system holds membership and service-contract information for up to 1,360,563 customer accounts.
The finding emerged from an investigation into an earlier intrusion into the company's Sakura Rental Server shared-hosting service, detected on 9 August, which involved unauthorized logins to 583 accounts and malware on company systems. While examining that incident, investigators found traces of access to the separate sales system, with activity dating back as far as April 2023.
What was exposed
The sales management system stored member IDs, names, company and department names, postal addresses, phone and fax numbers, email addresses, dates of birth, gender, subscribed services, contract periods and billing amounts. For 30 accounts, hashed password data may also have been accessed. Sakura Internet said payment card data was not stored in the system and that it had not confirmed large-scale exfiltration, describing the 1.36 million figure as the maximum possible scope.
Why it matters
Sakura Internet hosts websites and infrastructure for a large number of Japanese businesses, so customer contact and contract data is valuable for targeted phishing against its clients. The discovery that the attackers had been present in an internal business system for years, and that it surfaced only while investigating a smaller hosting compromise, shows how long intrusions can remain unnoticed in back-office systems.
Timeline
Sakura Internet detects unauthorized access to its Sakura Rental Server service, initially involving 583 accounts and malware on company systems.
In a second report, the company says it has found possible unauthorized access to its sales management system, potentially affecting 1,360,563 member accounts.
Japanese media report that the completed investigation traces the intrusion back about three years.
Sources
- itmedia.co.jphttps://www.itmedia.co.jp/news/article/2608/19/2000000629/
- atmarkit.itmedia.co.jphttps://atmarkit.itmedia.co.jp/ait/articles/2608/20/news036.html
- bitdefender.comhttps://www.bitdefender.com/en-us/blog/hotforsecurity/sakura-internet-breach-1-36-million-accounts
- teiss.co.ukhttps://www.teiss.co.uk/news/japanese-cloud-provider-sakura-internet-discloses-breach-affecting-136-million-members-18013