Japanese Cloud Provider Sakura Internet Hit by Massive Data Breach Exposing Up to 1.36 Million Accounts
A massive data breach has struck Japanese cloud and data center service provider Sakura Internet, potentially exposing sensitive information of up to 1.36 million member accounts. The incident occurred on August 9 when hackers accessed the company’s sales management system, where customer contract and membership details are stored.
Sakura Internet is a major player in Japan’s digital infrastructure market, offering a range of services including web hosting, virtual private servers (VPS), public cloud, data centers, and GPU computing. The company has been selected as a domestic provider for Japan’s Government Cloud program, making it a strategic entity that reduces the country’s dependence on foreign hyperscalers.
The breach was discovered during an investigation into a separate incident involving Sakura Rental Server service, which involved unauthorized logins to 583 accounts, access to customer-facing systems and client data, and the installation of malware onto Sakura’s systems. The company has invalidated all abused credentials and removed the malware, but the discovery of this larger exposure makes the incident even more significant.
According to an update from Sakura Internet, up to 1,360,563 member accounts may have been impacted by the breach. While no data exfiltration (theft) has been confirmed, it’s clear that hackers had access to sensitive information stored in the sales management system. Fortunately, Sakura Internet stores passwords as hashed values, which makes them harder to decipher even if stolen. Additionally, the compromised system does not store any credit card information.
The company has informed relevant authorities and is individually notifying affected customers about their data being exposed. While it’s unclear what type of malware was detected in Sakura’s environment, there have been no reports of ransomware or data extortion threats from attackers claiming responsibility for the breach.
This incident highlights the importance of robust security measures in protecting sensitive customer information. Once attackers gain valid credentials, prevention mechanisms can be ineffective, allowing them to access and manipulate data with ease. Organizations must prioritize multi-layered defenses that include continuous monitoring, threat intelligence, and incident response planning to mitigate such incidents.
In light of this breach, Sakura Internet’s customers should remain vigilant and take immediate action to secure their accounts. This includes changing passwords, enabling two-factor authentication (2FA), and regularly reviewing account activity for any suspicious behavior. By taking proactive steps to protect themselves, individuals can minimize the risk of falling victim to a data breach like this one.
Source: Bleeping Computer — 2026-08-19