Sakura Internet hack may affect 1.36 million accounts

Vlad CONSTANTINESCU

August 20, 2026

Sakura Internet hack may affect 1.36 million accounts

Japanese cloud and data center provider Sakura Internet is investigating unauthorized access to a sales management system that may have exposed personal and contract information linked to as many as 1.36 million customer accounts. The company says the final impact is under investigation and large-scale data exfiltration hasn’t been confirmed.

Key takeaways

  • Up to 1,360,563 Sakura Internet accounts potentially fall within the scope of the incident
  • Exposed information may include contact, profile, contract and billing details
  • Hashed password data associated with 30 accounts may also have been affected
  • Sakura says customer credit card information was not stored in the compromised system

Intrusion reaches Sakura Internet's sales system

Sakura Internet uncovered the broader compromise while investigating unauthorized access to its Sakura Rental Server service. That earlier incident affected 583 accounts, allowed attackers to reach customer environments and involved malware on company systems.

Investigators subsequently found evidence of possible unauthorized access to a separate sales management system holding membership and service-contract information. The activity occurred before Aug. 9, when the rental-server intrusion was detected, although Sakura has yet to determine whether the two events are directly connected.

Personal and contract data may have been exposed

Potentially affected records include member IDs, names, company and department information, addresses, phone numbers, email addresses, birth dates, gender, subscribed services, contract periods and billing amounts. Importantly, 1.36 million represents the maximum number of accounts possible within the scope, not a confirmed tally of stolen customer records.

Sakura also identified possible exposure of hashed passwords belonging to 30 accounts. The company says it has found no evidence that data was removed from the affected system, while credit card information was not stored there.

Customers should change passwords and watch for phishing

Sakura has revoked the credentials abused during the intrusion, removed malware, strengthened monitoring and brought in external specialists for forensic analysis. The company says it will contact customers who need to take specific action as investigators establish the final scope.

Customers can take precautions now by changing Sakura-related passwords, particularly FTP and email credentials, and replacing reused passwords on other services. Because leaked identity and contract information can make fraudulent messages more convincing, unexpected emails, attachments and links claiming to concern the breach should receive extra scrutiny.

Bitdefender Digital Identity Protection can monitor personal information for breach exposure and alert users when compromised data surfaces online or on the dark web.

Suspicious follow-up emails, texts, links or QR codes can also be checked with the free Bitdefender Scamio scam-detection service before users interact with them.

tags


Author


Vlad CONSTANTINESCU

Vlad's love for technology and writing created rich soil for his interest in cybersecurity to sprout into a full-on passion. Before becoming a Security Analyst, he covered tech and security topics.

View all posts

You might also like

Bookmarks


loader