Sakura Internet hack exposes data of up to 1.36 million accounts

Japanese cloud and data center service provider Sakura Internet has disclosed a major security incident that may have compromised up to 1.36 million customer accounts. The company’s sales management system, which stores sensitive information such as contract details and membership records, was accessed by hackers on August 9. The breach is particularly concerning due to the potential impact on customers who rely on Sakura Internet for their digital infrastructure needs.

Sakura Internet is a significant player in Japan’s tech industry, providing services including web hosting, VPS, public cloud, data center, and GPU computing solutions. Its involvement in Japan’s Government Cloud program makes it an important entity in reducing the country’s dependence on foreign hyperscalers. The company has been working to investigate the breach and notify affected customers, with the help of relevant authorities.

The incident was initially discovered during an investigation into a separate, less severe breach at Sakura Rental Server, which involved unauthorized logins to 583 accounts. However, it appears that the hackers also accessed the sales management system, potentially exposing sensitive customer information. According to Sakura Internet’s announcement, stored passwords are hashed and should be difficult to decipher even if stolen. The company has also stated that no credit card information is stored in the compromised system.

Despite the potential severity of the breach, there is currently no evidence of data exfiltration or ransom demands from attackers. Sakura Internet invalidated all abused credentials and removed malware from its systems, but the incident highlights the importance of robust security measures to prevent unauthorized access. The company’s decision to notify affected customers individually demonstrates a commitment to transparency and accountability.

The incident also serves as a reminder that even with strong prevention mechanisms in place, hackers can still gain access to sensitive information using valid credentials. According to recent research, once attackers have valid credentials, only 37% of their actions are blocked by security measures. This highlights the need for organizations to prioritize robust security protocols and continuous monitoring to detect and respond to potential threats.

As a result of this breach, customers of Sakura Internet should be vigilant about checking their accounts and credit reports for any suspicious activity. It’s also essential for organizations to review their own security practices and ensure they are taking adequate measures to prevent similar incidents in the future. By staying informed and proactive, individuals and businesses can minimize the risk of falling victim to such breaches.


Source: Bleeping Computer — 2026-08-19