Skip to content

Weekday Japan business intelligence for finance professionals.

Join the list
Tokyo Brief東 京 ブ リ ー フJapan's day, wrapped and delivered by morning.

Article

Sakura Internet's Closing Breach Report Puts Up to 1.36 Million Accounts in Scope

Sakura Internet's closing report on its 2026 intrusion says a customer database was reachable from April 2023 to March 2026, exposing up to 1,360,563 accounts and unhashed initial passwords, though the host maintains it has found no confirmed misuse to date.

Sep 10, 20263 min readSAKURA internet Inc.3778
Editorial illustration of a data center server rack with one section cordoned off for security remediation work.

Sakura Internet has closed the investigation into the unauthorized access first disclosed in August, and the final numbers are larger and older than the company's initial account suggested. The inquiry began with a maintenance-server anomaly detected on August 9 in the rental-server business, but investigators also found a separate intrusion into a customer database that had gone undetected for close to three years; the company says it found no clear evidence tying the two incidents together.

The hosting company's rental-server business, Sakura's Rental Server, saw its own tally of potentially affected accounts grow from the 583 disclosed on August 17 to 951, after follow-up investigation found 368 more accounts with similar exposure. Sakura could not confirm those additional 368 accounts were tied to the same intrusion, but treated them as in scope because it could not rule out impact. Separately, investigators found traces of suspicious activity in the rental-server environment dating to around July 2025; the company says this does not show a continuing breach or any secondary damage, but could not conclusively determine whether it connects to the main incident.

The bigger number sits in the sales management system, the database that holds contract and billing records for Sakura's customers across services, separate from the environments that actually run those services. Up to 1,360,563 member accounts had information potentially viewed or obtained by a third party, and the intrusion into that system ran from April 2023 to March 2026. Thirty of those accounts had hashed password data exposed. A different and more exposed set of credentials, unhashed initial server passwords for rental-server customers and unhashed initial administrator passwords for Sakura's VPS customers, was also stored in the same system.

Scope of Sakura Internet's Final Breach Report
Figures are the company's own estimate of accounts with information potentially viewed or obtained by a third party; not all listed data fields necessarily applied to every account.
SystemAccounts Potentially AffectedInformation Potentially Viewed
Sakura's Rental Server (customer environments)951 accountsUser identifiers and customer-stored content, including email data, website data, and log files
Sales management system (all affected members)Up to 1,360,563 accountsMember ID, company name, department, address, name, phone number, email, birth date, gender, fax number, contracted services, contract period, billing amounts
Subset of sales-management accounts30 accountsHashed member ID password data

Sakura says it has reset server passwords for rental-server customers confirmed to still be using an affected initial password, and has individually contacted VPS customers who may still be using theirs, asking them to change it. It holds no credit card data, so it says there is no card-leak risk tied to this incident.

On the central question, Sakura says it has found no clear evidence that data was taken outside the company, and no confirmed misuse of the exposed information or other secondary damage as of the report date. It is continuing to monitor the internet and dark web for signs the data has surfaced. The company expects only limited impact on the year to March 2027 consolidated results and does not currently plan to revise its earnings forecast. Remediation includes rebuilding every Sakura's Rental Server machine, widening EDR monitoring coverage, and adding periodic external audits and third-party assessments, alongside a stated commitment to elevate information security governance to management level.