Security3 publishers3 min readPublished
Sakura Internet's "contained" intrusion grows to 1.36 million accounts in two days
Sakura declared containment on a 583-account rental-server breach on August 17. On August 19 it said the attacker had also been in the sales-management system holding member records.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- Sakura Internet published a disclosure on 2026-08-17 titled "Unauthorized access to part of the environment of our rental server service".
- In an update dated 2026-08-19, Sakura Internet said that during continued investigation it confirmed the possibility of unauthorized access to the system that manages customers' contract information (the sales management system).
- Sakura Internet said it carried out containment measures including invalidating authentication credentials and blocking access, after which it continued to confirm the scope of impact.
- Sakura Internet said the total number of member accounts potentially affected is 1,360,563, and that this is not a number of confirmed impacts at this time.
- Sakura Internet said the 1,360,563 accounts include the already-disclosed Sakura Rental Server customers.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Sakura Internet said on August 19, 2026 that its continuing investigation into an intrusion at its rental server service had surfaced a second and much larger problem: possible unauthorized access to the sales management system that holds customer contract information [2]. The company put the number of member accounts potentially in scope at 1,360,563, while stressing that this is not a confirmed impact count [4].
The August 17 disclosure was narrower. It described unauthorized logins to 583 accounts on Sakura Rental Server, an attacker reaching areas from which customer accounts are accessible, malware installed on systems, and the possibility that personal data including some customer information was viewed or taken by a third party [11]. Sakura also said then that it had invalidated credentials, blocked access and carried out other necessary containment measures [3]. Forty-eight hours later the scope of accounts potentially involved was roughly 2,300 times larger [20][21].
The sequencing is the part worth reading twice. Sakura says the sales-management access was an event that occurred before August 9, the day it detected the intrusion into Sakura Rental Server, and that it is still investigating whether the two are related [10]. BleepingComputer, whose account SC Media relayed, dates the access to Sakura's IT system to August 9 itself [16][19]. Under either reading, the containment declared on the basis of the first finding was applied to the intrusion that was found first, not to the system that was reached earlier or at the same time.
On the data: Sakura says investigation of information stored in the sales management system found possible access to hashed password information for some customers, describing hashing only as leaving data in a state that is difficult to restore to the original password [6]. It says no external removal of data has been confirmed so far [7], that it does not store credit card information [8], and that the sales management system is separate from the environments that deliver its services, including Sakura Cloud [9]. The 1,360,563 figure includes the already-disclosed rental server customers rather than sitting on top of them [5]. "Not confirmed" is not "did not happen", and the confidence behind it belongs to an investigation that has already changed shape once.
Scale is why this is not just another hosting incident. Sakura provides web hosting, VPS, public cloud, data-center and GPU compute services in Japan [14], and has been selected as a domestic provider for the country's Government Cloud program, a role framed around reducing dependence on foreign hyperscalers [15]. Sakura says it has revoked the abused credentials, removed the malware, increased monitoring of related systems, engaged an external forensic firm, reported to relevant authorities and is notifying affected customers individually [12]. It added a link to an FAQ page for the incident in an 18:40 update on August 19 [13].
What to watch: whether the 1,360,563 figure moves down as forensics complete, or up [4][12]; whether Sakura concludes the two intrusions share an actor or an entry path [10]; and whether it ever names the hashing scheme behind the "difficult to restore" wording [6]. Also still open, per BleepingComputer: the malware family involved, with no service disruption reported and no extortion group claiming the attack [17][18].