Summary
- Sakura Internet's second incident notice added its sales-management system to the investigation and placed as many as 1,360,563 member accounts inside a possible affected population.
- The number is not a confirmed victim count. Sakura says it has not confirmed external data removal and that the management system is separate from service-delivery environments including Sakura Cloud.
The material change in Sakura Internet's 19 August update is a change of system, not merely a larger number. The first public notice concerned unauthorised logins to 583 accounts on Sakura Rental Server. The second said investigators had found possible unauthorised access to the system used to manage customer contracts and member information.
Sakura detected an abnormality in a company-managed server environment on 9 August. By 17 August it had confirmed that an attacker reached areas available to the 583 hosted customers and placed malware on some servers. Information stored there — including email, website data, logs and other customer files — might have been viewed or acquired.
The new sales-system access occurred before the 9 August detection, according to Sakura. The company is still investigating whether the two events are related. That leaves the entry path, dwell time, malware family and any lateral movement unresolved.
The headline denominator requires care. Sakura says 1,360,563 member accounts may be within the affected data population, but explicitly says this is not a count of accounts confirmed affected. Its official table lists member ID, company, department, address, name, telephone, email, date of birth, gender, fax, contracted service, contract period and billing amount among the fields that may have been accessible.
For 30 accounts within that population, hashed password information may also have been reachable. Sakura says it does not store credit-card information in the sales-management system. Neither statement removes credential or impersonation risk: a hash may still matter if it was copied, weak or paired with reused credentials, while contract data can support targeted fraud without a payment-card number.
At cutoff, Sakura had not confirmed that data had been taken outside its systems. That is an investigation state, not proof that no acquisition occurred. The company said it was continuing to determine what was actually viewed or obtained and was notifying customers individually.
The service boundary is equally important. Sakura describes the sales-management system as separate from service-delivery environments, including Sakura Cloud. Its first notice said Sakura VPS, Sakura Cloud, Dedicated Server PHY and Koukaryoku PHY were not confirmed affected at that time. BleepingComputer reported no disclosed operational disruption.
Those negative findings prevent a claim that Sakura's cloud platform or data-centre services were compromised. They do not prove containment. Segmentation is a control that forensic evidence must test: investigators still need to show which credentials crossed which boundary and whether any access path persisted.
Sakura says it invalidated potentially abused credentials, blocked access, removed malware, strengthened monitoring and engaged external forensic specialists. It also reported to authorities. On 20 August a spokesperson told BleepingComputer the incident was not ransomware-related and involved no ransom demand, while declining to identify the malware.
The operator's strategic position makes precision more important. Sakura provides hosting, cloud, data-centre and GPU services and has been selected as a domestic provider for Japan's Government Cloud programme. That context explains why the control boundary matters; it is not evidence that a Government Cloud workload was involved.
Sources
- https://www.sakura.ad.jp/corporate/information/newsreleases/2026/08/17/1968225614/
- https://www.sakura.ad.jp/corporate/information/newsreleases/2026/08/19/1968225633/
- https://www.sakura.ad.jp/corporate/wp-content/uploads/2026/08/c8a0305ac62526260baef24833f7602b.jpg
- https://www.bleepingcomputer.com/news/security/sakura-internet-hack-exposes-data-of-up-to-136-million-accounts/amp/
- https://ascii.jp/elem/000/004/427/4427853/
- https://www.itc.u-tokyo.ac.jp/education/services/webpark/news/page-4909-34/
- https://www.sakura.ad.jp/corporate/en/information/2026/03/27/1968224094/
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

