Sakura breach may affect 1.36M accounts
Japanese cloud and data center provider Sakura Internet says up to 1,360,563 member accounts may be exposed in a hack.
Japanese cloud and data center provider Sakura Internet has disclosed that hackers accessed its sales management system, potentially exposing data tied to up to 1,360,563 member accounts. In an update to an earlier notification, the company said the exact number of affected accounts remains under investigation, but the incident marks a significant escalation from a previously reported breach.
Timeline of the intrusion
According to Sakura Internet's announcement, hackers gained access to its IT systems on August 9. The breach was discovered later during the investigation of a separate incident involving the company's Sakura Rental Server service, which involved unauthorized logins to 583 accounts, access to customer-facing systems and client data, and the installation of malware onto Sakura's systems.
The company says it invalidated all abused credentials and removed the malware. However, the discovery of the larger exposure makes the incident more significant than initially thought. Sakura informed the relevant authorities of the hack and is individually notifying affected customers about their data being exposed.
Scope of the exposure
Based on data collected in the investigation so far, 1,360,563 accounts were potentially compromised, though no data exfiltration has been confirmed. The company stated that stored passwords are hashed and should be hard to decipher even if stolen, and the compromised system does not store any credit card information.
Strategic importance of Sakura Internet
Sakura Internet is a major Japanese digital infrastructure company providing web hosting, VPS, public cloud, data-center, and GPU computing services. It has been selected as a domestic provider for Japan's Government Cloud program, making it a strategic entity in the country that reduces dependence on foreign hyperscalers.
Unanswered questions
It is unclear what type of malware Sakura detected in its environment, but the firm did not mention any operational or service disruptions. BleepingComputer could not find a ransomware or data extortion threat actor claiming the attack on Sakura.
Why this matters for customers and the industry
This breach highlights the risks even to well-regarded infrastructure providers, especially those trusted with government-related workloads. For Sakura's customers, the immediate concern is the potential exposure of personal information, even if passwords are hashed and credit card data is not stored. The incident could also prompt a broader review of security practices among Japanese cloud providers, which are increasingly positioned as strategic alternatives to foreign hyperscalers. While no data theft has been confirmed, the scale of the potentially affected accounts underscores the importance of vigilance and robust incident response.
Sources
- BleepingComputer Original source
Continue Reading
ICE bans agents' Meta glasses in privacy reminder
ICE reminds employees that personal Meta glasses are prohibited workplace body-worn cameras
Linux Foundation's Akrites Set to Operationalize in September
The Linux Foundation's Akrites initiative plans to launch its vulnerability disclosure and remediation platform in September.
AI-Generated Scripts Target Siemens PLCs
Joint advisory warns of AI-powered attacks exploiting Siemens S7 PLCs across critical infrastructure sectors.