Cyber Security News

Sakura Internet Breach – Hackers Accessed 1.36 million Customers’ Personal Records

Sakura Internet has disclosed a potential breach involving its sales management system, placing the personal records of up to 1.36 million customer accounts at risk.

The Japanese cloud and hosting provider said the incident was identified during its ongoing investigation into unauthorized access affecting Sakura Rental Server environments.

The company initially announced the rental server intrusion on August 17, 2026. Sakura Internet later confirmed that attackers may also have accessed a separate system used to manage customer contracts and service-related information.

The newly identified access reportedly occurred before August 9, when the company detected the original unauthorized activity involving Sakura Rental Server.

Sakura Internet Breach

Sakura Internet said the sales management platform is separate from its service-delivery environments, including Sakura Cloud. However, the platform contains member and contract information, making the potential exposure significant for customers using its hosting and related services.

The company estimated that 1,360,563 customer accounts could be affected. It stressed that this figure represents accounts that may be impacted rather than confirmed victims. The total includes Sakura Rental Server customers already covered by the earlier disclosure.

Information that an attacker could access includes customer and member data stored in the sales management system. Sakura Internet also confirmed that some accounts may have had hashed password information exposed.

Hashed passwords are transformed versions of original passwords designed to make direct recovery more difficult. However, they can still pose a risk if weak or reused passwords are targeted in offline cracking attempts.

The company said it does not store customer credit card information in the affected environment. It also stated that, as of its latest update, it had not confirmed any data exfiltration from its systems.

Investigators are continuing to determine which information was viewed, obtained, or potentially removed by the attacker. The original Sakura Rental Server incident affected 583 accounts through unauthorized logins.

Sakura Internet said attackers gained access sufficient to enter affected customer environments and install malware. Personal data belonging to some rental server customers may also have been viewed or obtained during that intrusion.

Sakura Internet has invalidated authentication credentials believed to be involved in the unauthorized access, blocked attacker access paths, removed malware, and increased monitoring across relevant systems.

The provider has also engaged an external forensic organization to investigate the incident, identify the attack path, and establish whether the sales management compromise is connected to the rental server breach.

The company said it is notifying affected customers individually and sharing information with relevant organizations. It plans to publish further updates if additional facts requiring disclosure are identified.

Customers should treat Sakura Internet-related emails, password-reset notices, and support communications with caution. Users should change Sakura Internet passwords, avoid password reuse across services, enable multi-factor authentication where available, and monitor accounts for suspicious login activity.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

16 hours ago