
Japanese cloud and data center provider Sakura Internet is investigating unauthorized access to a sales management system that may have exposed personal and contract information linked to as many as 1.36 million customer accounts. The company says the final impact is under investigation and large-scale data exfiltration hasn’t been confirmed.
Sakura Internet uncovered the broader compromise while investigating unauthorized access to its Sakura Rental Server service. That earlier incident affected 583 accounts, allowed attackers to reach customer environments and involved malware on company systems.
Investigators subsequently found evidence of possible unauthorized access to a separate sales management system holding membership and service-contract information. The activity occurred before Aug. 9, when the rental-server intrusion was detected, although Sakura has yet to determine whether the two events are directly connected.
Potentially affected records include member IDs, names, company and department information, addresses, phone numbers, email addresses, birth dates, gender, subscribed services, contract periods and billing amounts. Importantly, 1.36 million represents the maximum number of accounts possible within the scope, not a confirmed tally of stolen customer records.
Sakura also identified possible exposure of hashed passwords belonging to 30 accounts. The company says it has found no evidence that data was removed from the affected system, while credit card information was not stored there.
Sakura has revoked the credentials abused during the intrusion, removed malware, strengthened monitoring and brought in external specialists for forensic analysis. The company says it will contact customers who need to take specific action as investigators establish the final scope.
Customers can take precautions now by changing Sakura-related passwords, particularly FTP and email credentials, and replacing reused passwords on other services. Because leaked identity and contract information can make fraudulent messages more convincing, unexpected emails, attachments and links claiming to concern the breach should receive extra scrutiny.
Bitdefender Digital Identity Protection can monitor personal information for breach exposure and alert users when compromised data surfaces online or on the dark web.
Suspicious follow-up emails, texts, links or QR codes can also be checked with the free Bitdefender Scamio scam-detection service before users interact with them.
tags
Vlad's love for technology and writing created rich soil for his interest in cybersecurity to sprout into a full-on passion. Before becoming a Security Analyst, he covered tech and security topics.
View all posts