Rakuten Drive — Rakuten Group’s consumer cloud storage service — told users that compromised administrator credentials allowed unauthorized parties to view stored files belonging to 15,382 accounts between January 29 and September 17, 2026. On August 27, 2026, attackers also accessed detailed information on 687 accounts, including 313 encrypted passwords, according to the official support notice 62934949147929 and reporting from ASCII.jp. Canonical BreachHistory record: https://breachhistory.com/rakuten-drive/rakuten-drive2026 (/rakuten-drive/rakuten-drive2026).
This is a verified Rakuten Drive data breach disclosure — dates, account counts, and access types come from Rakuten’s own notice — not a leak-site listing or forum dump. What this is not: a headline breach of every Rakuten Ichiba shopper or Rakuten Bank account; indexed materials describe the Drive product’s user base and admin path, not the whole conglomerate.
What happened — eight months of admin access
Cloud storage incidents often surface late because users do not see “failed login” banners on files they uploaded months ago. Rakuten Drive’s published window — late January through mid-September 2026 — implies long dwell on privileged credentials. Someone with admin-class access can browse object stores, list folders, and open documents without knowing each customer’s password.
The August 27 spike is a forensic bookmark. 687 accounts saw deeper “account detail” access, and 313 encrypted passwords were caught in that phase. Rakuten has not, in indexed English summaries, explained whether that cohort overlaps the 15,382 file-view set or represents a separate admin workflow (support console export, auth backend query, etc.). If you receive individual notice citing August 27, treat password rotation as mandatory.
ASCII.jp’s October coverage gives Japanese readers independent tech-press context; English speakers should still open the official support article with translation rather than trusting reposts that merge this row with unrelated historical Rakuten ecommerce breaches.
Timeline
- January 29, 2026 — Unauthorized access period begins (per Rakuten Drive notice).
- August 27, 2026 — Detailed access to 687 accounts; 313 encrypted passwords in scope.
- September 17, 2026 — Last observed unauthorized access in the attested interval.
- October 2026 — Public customer notification via Rakuten Drive support center; ASCII.jp reporting.
What remains unknown in public notices
- Initial access vector — phishing an ops engineer, stolen API key, support portal bug, or insider abuse — not named in indexed materials.
- Per-file manifest — which documents or photos were opened for each of the 15,382 accounts.
- Whether exfiltration occurred — viewing in-console vs bulk download to attacker infrastructure.
- Full overlap between the 15,382 set and the 687 August 27 cohort.
What data was exposed
For 15,382 accounts, attackers could view stored data — the files users uploaded (documents, images, backups, and whatever else lived in Drive). Rakuten’s notice centers on confidentiality of those objects, not a fixed column list like a retail loyalty database.
For the 687-account August event, account details were accessed and 313 encrypted passwords were exposed in encrypted form. “Encrypted” here usually means hashed or encrypted at rest; offline cracking still threatens weak user-chosen passwords.
What was not exposed — per notice framing
Indexed summaries emphasize file viewing and the August credential-metadata event rather than payment card numbers or a whole-Rakuten-ID database dump. That does not mean you should ignore cross-service password reuse: many subscribers use one Rakuten ID across Ichiba, mobile, and Drive.
Absence of “credit card leaked” language in the Drive notice is not a guarantee that no uploaded file contained card scans or bank PDFs — users often store those voluntarily in cloud drives.
How admin credential compromise works
Consumer cloud products depend on small teams of administrators who can impersonate support actions, reset sessions, and enumerate tenants. When those credentials leak — via phishing, malware on an engineer laptop, or a misconfigured CI secret — attackers inherit visibility equal to the admin role, not equal to one user password.
Eight-month dwell suggests missed alerts on privileged API usage: bulk object listing, off-hours admin logins, or cross-tenant queries. SaaS operators should treat this incident as a case study in admin MFA, just-in-time roles, and immutable audit logs.
Who is at risk
Users among the 15,382 accounts should assume sensitive uploads may have been seen — tax forms, insurance papers, ID scans, legal contracts, family photos with geotags.
The 687 / 313-password cohort faces elevated credential-stuffing and offline hash cracking; rotate Drive and Rakuten ID passwords and enable MFA on the email used for resets.
Freelancers and small businesses using Drive for client deliverables may owe third-party breach notices under APPI if client files were visible.
Households sharing one Drive account widen impact when one member uploaded medical or school records others forgot about.
Phishing after the Rakuten Drive breach 2026
- Fake “Rakuten Drive security upgrade” login pages asking for Rakuten ID and OTP.
- Emails citing August 27 to push malware disguised as password reset tools.
- Support impersonation claiming your files will be deleted unless you pay a fee.
Rakuten ID and password reuse
Rakuten Group pushes a unified identity across shopping, mobile, fintech, and storage. A hash stolen from Drive infrastructure does not automatically unlock Ichiba checkout, but humans reuse passwords. If your Drive password matched other Rakuten or personal sites, rotate all of them — unique passphrases via a password manager, MFA on email.
Industry context — Japan cloud and October 2026 retail leaks
Drive users share headline space with app-member breaches at restaurant and discount chains the same week — different products, same criminal appetite for Japanese contact data. The Times Car breach exposed mobility-account fields including license images; Drive’s harm is file confidentiality, not DMV scans — assess each canonical row separately.
Cloud storage sits quietly in breach roundups until someone remembers their My Number scan lived in a folder synced in March. Compare also the Tokyo Metro Metpo email incident — email-only exposure with a shorter window — for how field mix changes advice.
What Rakuten Drive said publicly
The controlling artifact is support article 62934949147929. It anchors dates, the 15,382 account figure, the August 27 sub-event, and encrypted-password language. ASCII.jp provides secondary Japanese tech press summary for readers who want independent confirmation that a notice exists.
What you should do
- Change Rakuten Drive and Rakuten ID passwords if you used the service during the window — unique strings, not reused on email or banking.
- Enable MFA on Rakuten ID and on the inbox that receives password resets.
- Inventory uploads between January 29 and September 17; assume identity documents in that window were viewed.
- Delete stale sensitive files you no longer need online; keep offline encrypted copies if required.
- Notify clients if shared folders held their contracts or PII.
- Reject sideload apps or APK “Rakuten Drive fixes” from SMS links.
- Bookmark /rakuten-drive/rakuten-drive2026 for count or scope updates.
- Watch official support — not paste sites advertising a “full Rakuten dump.”
Encrypted passwords — practical meaning
Vendor phrasing “encrypted passwords” rarely means attackers downloaded plaintext. It does mean offline attacks against weak passwords are in scope for the 313-user subset. If you ever used a short or reused password on Drive, assume it is being cracked in a queue somewhere.
Defender checklist for cloud operators
- Hardware MFA on all admin and support consoles.
- Alert on cross-tenant object listing and mass metadata export.
- Session recording for privileged actions with tamper-evident storage.
- Customer comms that distinguish file viewing from credential-field access.
Was I affected?
You may be in scope if you held an active Rakuten Drive account between January 29 and September 17, 2026, especially if Rakuten notifies you or if you used the service heavily during that period. Lack of email at indexing time does not prove safety — notification waves lag, and Japanese primary notices may arrive before English summaries.
Long-term monitoring
File-view breaches age poorly: tax season, loan applications, and visa renewals reuse the same scans attackers may have browsed in summer. Keep monitoring credit and identity if you stored financial PDFs in Drive during the window.
APPI and notification expectations
Japanese personal-data rules may require Rakuten to notify the Personal Information Protection Commission and affected users with field-level detail when forensics finish. English trade coverage in October may arrive before every user email — especially for dormant accounts with old uploads still on disk. Retain PDF screenshots of the support notice if your bank or employer later asks for documentation of third-party exposure.
Reading “view” vs “download” in vendor notices
Rakuten’s wording that attackers “viewed” stored data leaves room for interpretation: streaming an image in an admin console still violates confidentiality even if no zip file left Rakuten’s data center. Defenders should not downgrade risk because a notice avoids the word “exfiltrated.” Assume hostile copies unless a later forensic statement proves console-only access with logging and no export paths.
Incident response lessons for subscribers
If you used Drive for side-business bookkeeping, client contracts, or employee records, your incident is also a small-business compliance event. Document what you stored, when you stored it, and which clients you must warn. APPI’s focus on third-party handlers applies to you when your cloud vendor loses admin control — not only when you lose a laptop.
Geotagged photos and indirect exposure
Family albums and vacation photos often embed GPS coordinates. A “view” event on those files leaks location history even when the notice never lists “address” as a database column. Review albums uploaded during the window; strip EXIF before re-uploading elsewhere if you repatriate files after deleting them from Drive.
Support impersonation and OTP harvest
Post-notice scams will cite the January–September window and August 27 password language. Real Rakuten support will not ask you to read a one-time code aloud on a cold call or install remote-access software to “verify your Drive vault.” Hang up, open the support site from a bookmark, and initiate chat yourself.
Shared devices and family accounts
Drive folders often back up a whole household’s paperwork from one login. A teenager’s school forms, a parent’s hospital discharge PDF, and a side-hustle invoice may share the same tenant. If Rakuten later publishes affected account IDs, assume everyone who relied on that login during the window shares the blast radius — even people who never opened the Drive app themselves.
Comparing cloud file exposure to contact-only retail leaks
Restaurant and discount-app breaches this October mostly leaked names, emails, and phones — painful for phishing, but not the same as someone scrolling your uploaded documents. Drive sits closer to laptop theft than to a loyalty-table leak. That distinction should drive your response: prioritize inventory of files over credit freeze alone unless financial PDFs were in scope.
Backup habits and shadow copies
Users sometimes treat cloud drives as the only copy of tax or medical PDFs. If you delete local copies after upload, Rakuten’s incident becomes your only recovery path — and attackers may have seen those files before you do. Export anything critical to offline encrypted storage after rotating credentials, even if Rakuten later offers credit monitoring or support hotlines.
Enterprise tenants on consumer SKUs
Small teams occasionally share one Drive login for project folders. If that shared login falls inside the 15,382 set, contractual NDAs and client confidentiality clauses may trigger regardless of whether Rakuten labels the account “consumer.” Legal and IT should read the support notice together rather than assuming “cloud” equals low severity.
Rakuten’s three numbered events — what each cohort means
Rakuten Drive’s customer notice splits the intrusion into three labeled events rather than one blended statistic. That matters for notifications: you might receive mail referencing only profile metadata, only encrypted password material, or only file access — depending on which bucket forensics placed your account.
Event 1 (August 27, 2026) touched 687 accounts. Attackers viewed account names, display names shown during file sharing, and profile-image URLs. No password fields appear in that bucket’s list.
Event 2 (August 27, 2026) touched 313 accounts, a subset that also included encrypted passwords plus the additional random strings Rakuten uses to make password recovery harder. Rakuten stresses those passwords were transformed so restoration should be difficult — industry phrasing for salted hashes or similar one-way transforms, not a promise that offline cracking is impossible.
Event 3 (January 29 through September 17, 2026) is the largest slice: 15,382 accounts whose stored Drive content — photos, documents, and other uploaded objects — was accessed or viewed. That eight-month window is the headline dwell time; ASCII.jp’s October 6 reporting echoes the same figures for Japanese readers.
Service restrictions Rakuten imposed
After detecting abuse, Rakuten said it blocked the unauthorized access path, strengthened monitoring, restricted mobile app downloads, and limited new account registration while response work continued. Those product-level brakes are easy to miss in breach summaries focused only on victim counts, but they signal the operator treated admin compromise as an active production incident — not a historical log review.
Rakuten also reported the matter to relevant authorities and promised individual email outreach to affected customers. A dedicated hotline (0800-600-6600, 9:00–17:00 daily, Japanese only) appears in the notice for people who see suspicious login alerts or impersonation attempts tied to Drive.
Display names and shared folders
Display names leak sounds harmless until you remember they appear beside shared links. An attacker who viewed profile metadata on August 27 can craft spear-phishing that quotes the nickname your friends expect in collaboration invites. Combine that with knowledge that you use Rakuten Drive for backups, and a fake “shared folder expired — reauthenticate” message becomes plausible.
Profile-image URLs may reveal which avatar you use across services if those URLs are stable and public. They rarely enable account takeover alone, but they help attackers prioritize targets whose folders might hold scans of passports or contracts.
What Rakuten has not confirmed publicly
The indexed notice does not specify malware families, stolen laptop narratives, or whether admin credentials came from phishing, a supplier, or an insider. It also does not publish a per-account manifest of which files were opened. “Viewed” could mean streaming in an operations console or copying objects to external storage — customers should assume hostile retention until a later forensic statement narrows the scope.
Canonical record and sources
BreachHistory indexes Rakuten Drive as company-confirmed unauthorized admin access with 15,382 accounts’ files viewed and an August 27 detail event affecting 687 accounts (313 encrypted passwords). Update at https://breachhistory.com/rakuten-drive/rakuten-drive2026 if Rakuten revises scope.
Long-dwell admin access turns a cloud drive into a read-only window on private life. Rakuten Drive subscribers should rotate credentials, harden MFA, and assume January-through-September uploads were visible to someone who should not have been there — then watch official channels for any narrower file list or expanded cohort as forensics continue.