Sakura Internet Breach Exposes Personal Data of Up to 1.36 Million Customers
Japanese cloud provider Sakura Internet disclosed a breach affecting its sales management system, potentially exposing personal data of up to 1.36 million customers, including hashed passwords.

Sakura Internet, a prominent Japanese cloud and hosting provider, has announced a significant data breach impacting its sales management system, potentially compromising the personal records of up to 1.36 million customer accounts. The incident came to light during an ongoing investigation into unauthorized access that had previously affected the company's Sakura Rental Server environments. This newly identified compromise occurred prior to August 9, 2026, when the initial unauthorized activity on the rental servers was detected.
The compromised sales management platform, while separate from Sakura Internet's core service delivery environments like Sakura Cloud, contains sensitive member and contract information. This makes the potential exposure a serious concern for customers utilizing the company's wide range of hosting and related services. The provider has estimated that approximately 1,360,563 customer accounts could be affected, clarifying that this figure represents accounts that may have been impacted rather than a confirmed count of victims. This total also encompasses customers whose data may have been compromised in the earlier rental server breach.
Information potentially accessed by the attackers includes customer and member data stored within the sales management system. Crucially, Sakura Internet confirmed that some accounts may have had their hashed password information exposed. While hashed passwords are designed to be difficult to reverse, they can still pose a risk if weak or commonly reused passwords are targeted through offline cracking techniques. The company has stated that no customer credit card information was stored in the affected system, and as of its latest update, no definitive data exfiltration had been confirmed.
The initial incident involving Sakura Rental Server affected 583 accounts through unauthorized logins, with attackers gaining sufficient access to enter customer environments and install malware. Personal data belonging to some of these rental server customers may also have been viewed or obtained during that intrusion. The ongoing forensic investigation is working to determine the full extent of data exfiltration, including precisely which information was viewed, obtained, or potentially removed by the attacker.
In response to the breaches, Sakura Internet has taken several immediate security measures. Authentication credentials believed to be involved in the unauthorized access have been invalidated, attacker access paths have been blocked, and any identified malware has been removed. The company has also enhanced monitoring across its relevant systems. To further investigate the incident, identify the precise attack vectors, and determine any connection between the sales management system compromise and the rental server breach, Sakura Internet has engaged an external forensic organization.
Sakura Internet is in the process of notifying affected customers individually and is cooperating with relevant organizations. The company has pledged to provide further updates should additional facts requiring disclosure emerge. Customers are advised to exercise caution with all communications purportedly from Sakura Internet, including emails, password reset notifications, and support messages. Recommended security practices include changing Sakura Internet passwords, avoiding password reuse across different services, enabling multi-factor authentication wherever possible, and closely monitoring accounts for any signs of suspicious login activity.