< Back to all clusters
[TECHNOLOGY] · Japan · 2 sources

started · updated

Sakura Internet reports breach affecting 1.36 million accounts

Sakura Internet has released the results of an investigation into unauthorized access to its systems, revealing that a breach of its sales management system persisted for approximately three years, from April 2023 to March 2026.

The company reported that 1,360,563 accounts may have had member and contract information viewed or acquired by a third party. This information includes names, addresses, phone numbers, email addresses, dates of birth, and billing amounts. While the scale is large, the company stated there is no confirmed evidence that data was exfiltrated or used for secondary damages such as phishing or financial fraud. Credit card information was not stored in the system and remains secure.

Additionally, the investigation into ‘Sakura Rental Server’ identified 951 accounts where information—including user identifiers, email data, and website data—may have been accessed.

A significant security lapse was discovered: some initial passwords for rental servers and VPS (Virtual Private Servers) were stored in plain text without being hashed. Sakura Internet has since taken measures to invalidate these credentials and has requested affected customers to change their passwords.

Entities

Sakura Internet