2026 Rakuten Drive — stolen admin credentials; 15,382 accounts’ stored files accessed
Data compromised
Jan 29–Sep 17 2026: stored data (photos, documents, etc.) for 15,382 accounts viewed/obtained. Aug 27: account names, display names, profile image URLs for 687 accounts; encrypted passwords + hardening strings for 313 of those. No secondary damage confirmed; new downloads/account issuance restricted.
Technical writeup
Verified company notice — Rakuten Symphony (Rakuten Drive) Oct 6, 2026: unauthorized third-party access after administrative credentials were obtained. Largest impact window Jan 29–Sep 17, 2026: stored content for 15,382 accounts (photos/documents) viewed. Aug 27: 687 accounts’ names/display names/profile URLs accessed; 313 of those also had encrypted passwords and salt-like strings viewed (company says passwords processed to resist recovery). Intrusion paths blocked; app download and new account issuance restricted; authorities notified; users messaged individually. recordsAffected 15382; companyConfirmed true.
Root cause
Administrative account credentials illicitly obtained, enabling unauthorized access to Rakuten Drive systems (Rakuten Symphony disclosure Oct 6, 2026).