← Sakura Internet

2026 Sakura Internet — sales-mgmt breach; up to 1.36M member accounts (malware path; rental-server tie-in)

2026 1.4M records affected Share on X

Data compromised

Customer contract and membership information in sales management system for up to 1,360,563 member accounts; passwords stored hashed per company; no credit card data in affected system; no confirmed exfiltration at Aug 19 update

Technical writeup

Verified company disclosure — August 19, 2026 update. Sakura Internet (major Japanese hosting/cloud/data-center operator and Government Cloud domestic provider) said hackers accessed its IT environment on August 9, 2026. The exposure was identified while investigating a separate Sakura Rental Server incident that involved unauthorized logins to 583 accounts, access to customer-facing systems and client data, and malware on Sakura systems (credentials invalidated and malware removed per company). The broader sales management system storing customer contract and membership data may have impacted up to 1,360,563 member accounts; Sakura says investigation continues and the exact affected count is not final. Company states no data exfiltration has been confirmed so far; stored passwords are hashed and the compromised system did not hold credit card information. Sakura notified authorities and is individually notifying affected customers. No ransomware group claim identified in BleepingComputer reporting at indexing. recordsAffected 1360563 from company upper-bound notice.

Root cause

Unauthorized access to IT systems Aug 9, 2026; discovered during Sakura Rental Server incident investigation; malware installed; 583 rental-server accounts also hit separately

References