Sakura Internet Says Breach May Have Exposed 1.36 Million Customer Accounts

The Japanese cloud provider, a chosen supplier for Japan's Government Cloud, found the wider intrusion while investigating a smaller hack of its rental server service.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
A Japanese data center facility with security personnel reviewing incident reports on screens, breach investigation documents visible on desks, government cloud
Share

Key points

  • Sakura Internet disclosed that hackers reached a sales management system holding contract and membership data for up to 1,360,563 accounts.
  • The intrusion began on 9 August 2024 and was uncovered while the company investigated a separate breach of its Sakura Rental Server service.
  • The smaller Rental Server incident involved unauthorised logins to 583 accounts and malware planted on Sakura systems.
  • Passwords were stored in hashed form and no credit card details were held in the affected system, according to the company.
  • No ransomware group or extortion crew has publicly claimed the attack.

Sakura Internet, one of Japan's larger cloud and data centre operators, says criminals broke into a sales management system storing customer contract and membership records. The potential exposure: 1,360,563 accounts.

Outside Japan it's barely known. Inside Japan it matters considerably: the company runs web hosting, virtual private servers, public cloud, GPU computing and data centre services, and was picked as a domestic supplier for Japan's Government Cloud programme, a scheme designed to cut reliance on foreign hyperscalers like AWS and Microsoft.

What actually happened?

Hackers got into Sakura's IT system on 9 August 2024. Staff found the wider intrusion later, while investigating a separate, smaller break-in at the Sakura Rental Server product.

That smaller incident, first reported by BleepingComputer, involved unauthorised logins to 583 customer accounts, access to customer-facing systems and client data, and malware planted on Sakura's own machines. Sakura invalidated the abused credentials and removed the malware. Digging further, it found the bigger problem.

Who is affected and what was exposed?

Up to 1,360,563 member accounts may have been touched. Sakura hasn't confirmed any data was copied out, only that attackers had access to the system holding it.

Stored passwords are hashed, meaning scrambled with a one-way mathematical function that's hard to reverse. The affected system holds no credit card numbers. Contract and membership details are a different matter, and the company is contacting affected customers directly.

Detail Figure
Accounts potentially exposed 1,360,563
Rental Server accounts with unauthorised logins 583
Date of initial intrusion 9 August 2024
Credit card data exposed None held in system
Confirmed data theft Not confirmed

Two days before this disclosure, we reported on Heights Finance's breach of 1.2 million borrower records, where cloud storage was the entry point. Sakura's incident shares the pattern: large account counts, no confirmed exfiltration at disclosure, and direct customer notification underway.

Should Sakura customers be worried?

Customers should be alert, not panicked. No card details were in the system, and hashed passwords make straight account takeover harder. The real risk is targeted phishing: criminals armed with real contract details can send convincing fake emails from a company whose name you recognise and whose services you actually use.

Change your Sakura password now, enable two-factor authentication if you haven't, and treat any email asking you to log in via a link with suspicion.

Who is behind it?

Nobody has claimed the attack. No ransomware crew has listed Sakura on a leak site, and no extortion group has publicly demanded payment. Sakura hasn't said what malware family was found on its systems and reports no service disruptions tied to the incident.

Japanese authorities have been informed and the investigation continues. The account count could still change. What makes this worth watching is Sakura's role in Japan's Government Cloud: a breach at a strategic national supplier, however contained, tends to get a second look from regulators.

© 2026 Threat Vectr