Sakura Internet Says Breach May Have Exposed 1.36 Million Customer Accounts
The Japanese cloud provider, a chosen supplier for Japan's Government Cloud, found the wider intrusion while investigating a smaller hack of its rental server service.

Key points
- Sakura Internet disclosed that hackers reached a sales management system holding contract and membership data for up to 1,360,563 accounts.
- The intrusion began on 9 August 2024 and was uncovered while the company investigated a separate breach of its Sakura Rental Server service.
- The smaller Rental Server incident involved unauthorised logins to 583 accounts and the installation of malware on Sakura systems.
- Passwords were stored in hashed form and no credit card details were held in the affected system, according to the company.
- No ransomware group or extortion crew has publicly claimed the attack.
Sakura Internet, one of Japan's larger cloud and data centre operators, says criminals broke into a sales management system that stores customer contract and membership records. The company puts the potential exposure at 1,360,563 accounts.
The firm is not a household name outside Japan, but it matters at home. It runs web hosting, virtual private servers, public cloud, data centres and GPU computing services, and it was picked as a domestic supplier for Japan's Government Cloud programme, a scheme designed to cut the country's reliance on foreign giants like AWS and Microsoft.
What actually happened?
Hackers got into Sakura's IT system on 9 August 2024. Staff only discovered the wider intrusion later, while looking into a separate, smaller break-in at the company's Sakura Rental Server product.
That smaller incident, first reported by BleepingComputer, involved unauthorised logins to 583 customer accounts, access to customer-facing systems, and malware planted on Sakura's own machines. Sakura says it cancelled the abused passwords and removed the malware. Then, digging further, it found the bigger problem next door.
Who is affected and what was exposed?
Up to 1,360,563 member accounts may have been touched. The company has not confirmed that any data was actually copied out, only that attackers had access to the system that holds it.
Sakura says stored passwords are hashed, meaning they are scrambled with a one-way mathematical function that is hard to reverse. It also says the affected system does not hold credit card numbers. Contract details and membership information are a different matter, and the company is contacting affected customers directly.
| Detail | Figure |
|---|---|
| Accounts potentially exposed | 1,360,563 |
| Rental Server accounts with unauthorised logins | 583 |
| Date of initial intrusion | 9 August 2024 |
| Credit card data exposed | None held in system |
| Confirmed data theft | Not confirmed |
Should Sakura customers be worried?
Customers should be alert but not panicked. No card details were in the system, and passwords were hashed, so straight account takeover is not the immediate risk. The bigger worry is targeted phishing, where criminals send fake emails pretending to be Sakura, using real contract details to sound convincing.
If you have a Sakura account, change the password now, turn on two-factor authentication if you have not already, and treat any email claiming to be from the company with suspicion, especially if it asks you to log in via a link.
Who is behind it?
Nobody has claimed the attack. No ransomware crew has listed Sakura on a leak site, and no extortion group has publicly demanded payment. Sakura has not said what family of malware was found on its systems, and it reports no service outages tied to the incident.
The company has informed Japanese authorities and says its investigation continues. The final count of affected accounts could still move.



