Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
2 clusters · 2 sources · 25 days · First seen · Last updated
Sakura Internet data breach
Overview
Sakura Internet initially reported unauthorized third-party access to its Sakura Rental Server environment, which was detected on August 9. The company confirmed that 583 accounts were victims of unauthorized logins, with attackers potentially accessing personal data and malware being discovered on some servers. In response, the company invalidated credentials, blocked unauthorized access paths, and restricted certain service functions while conducting a forensic investigation.
Subsequent investigation results revealed a much larger breach involving the company’s sales management system, which persisted for approximately three years from April 2023 to March 2026. This breach potentially affected 1,360,563 accounts, exposing member and contract information such as names, addresses, phone numbers, and email addresses. While the company stated there was no confirmed evidence of data exfiltration for secondary damages, it noted that credit card information remained secure as it was not stored in the system.
Additionally, the investigation into the Sakura Rental Server identified 951 accounts where user identifiers, email, and website data may have been accessed. The company also discovered a security lapse where some initial passwords for rental servers and VPS were stored in plain text without being hashed.
Entities
Timeline
-
about 13 hours ago
[TECHNOLOGY] 2 sourcesSakura Internet reports breach affecting 1.36 million accountsSakura Internet reported a long-term breach affecting 1.36 million accounts via its sales management system and 951 rental server accounts, noting that some initial passwords were stored without hashing.
-
26 days ago
[TECHNOLOGY] 8 sourcesSakura Internet reports unauthorized access to 583 rental server accountsSakura Internet reported unauthorized access to 583 Sakura Rental Server accounts, potentially exposing customer data and communications. Malware was found, and some service functions have been restricted.
Sources
atmarkit.co.jp · weekly.ascii.jp