Security3 distinct publishers3 min readUpdated
Sakura declared containment on a 583-account rental-server breach on August 17. On August 19 it said the attacker had also been in the sales-management system holding member records.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Sakura Internet said on August 19, 2026 that its continuing investigation into an intrusion at its rental server service had surfaced a second and much larger problem: possible unauthorized access to the sales management system that holds customer contract information [2]. The company put the number of member accounts potentially in scope at 1,360,563, while stressing that this is not a confirmed impact count [4].
The August 17 disclosure was narrower. It described unauthorized logins to 583 accounts on Sakura Rental Server, an attacker reaching areas from which customer accounts are accessible, malware installed on systems, and the possibility that personal data including some customer information was viewed or taken by a third party [11]. Sakura also said then that it had invalidated credentials, blocked access and carried out other necessary containment measures [3]. Forty-eight hours later the scope of accounts potentially involved was roughly 2,300 times larger [20][21].
The sequencing is the part worth reading twice. Sakura says the sales-management access was an event that occurred before August 9, the day it detected the intrusion into Sakura Rental Server, and that it is still investigating whether the two are related [10]. BleepingComputer, whose account SC Media relayed, dates the access to Sakura's IT system to August 9 itself [16][19]. Under either reading, the containment declared on the basis of the first finding was applied to the intrusion that was found first, not to the system that was reached earlier or at the same time.
On the data: Sakura says investigation of information stored in the sales management system found possible access to hashed password information for some customers, describing hashing only as leaving data in a state that is difficult to restore to the original password [6]. It says no external removal of data has been confirmed so far [7], that it does not store credit card information [8], and that the sales management system is separate from the environments that deliver its services, including Sakura Cloud [9]. The 1,360,563 figure includes the already-disclosed rental server customers rather than sitting on top of them [5]. "Not confirmed" is not "did not happen", and the confidence behind it belongs to an investigation that has already changed shape once.
Scale is why this is not just another hosting incident. Sakura provides web hosting, VPS, public cloud, data-center and GPU compute services in Japan [14], and has been selected as a domestic provider for the country's Government Cloud program, a role framed around reducing dependence on foreign hyperscalers [15]. Sakura says it has revoked the abused credentials, removed the malware, increased monitoring of related systems, engaged an external forensic firm, reported to relevant authorities and is notifying affected customers individually [12]. It added a link to an FAQ page for the incident in an 18:40 update on August 19 [13].
What to watch: whether the 1,360,563 figure moves down as forensics complete, or up [4][12]; whether Sakura concludes the two intrusions share an actor or an entry path [10]; and whether it ever names the hashing scheme behind the "difficult to restore" wording [6]. Also still open, per BleepingComputer: the malware family involved, with no service disruption reported and no extortion group claiming the attack [17][18].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
In an update dated 2026-08-19, Sakura Internet said that during continued investigation it confirmed the possibility of unauthorized access to the system that manages customers' contract information (the sales management system).
Sakura Internet said the total number of member accounts potentially affected is 1,360,563, and that this is not a number of confirmed impacts at this time.
Sakura Internet said the 1,360,563 accounts include the already-disclosed Sakura Rental Server customers.
Sakura Internet said investigation of information stored in the sales management system confirmed the possibility of access to hashed password information for some customers, defining hashed passwords as data placed in a state where restoring the original password is difficult.
Sakura Internet said that at present no external removal (exfiltration) of data has been confirmed.
Sakura Internet published a disclosure on 2026-08-17 titled "Unauthorized access to part of the environment of our rental server service".
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Strong first-party documentation, thin independent verification
The factual spine is a detailed, dated first-party release with numbered sections, explicit scope caveats and a response checklist, and BleepingComputer independently reproduces the key figures. Depth is limited by the fact that the second outlet is an acknowledged aggregation of the first, and that root cause, malware identity and the intrusion timeline are unresolved even in the primary document.
Vendor-confirmed events at scale; impact still unconfirmed
This is a real, disclosed and acted-upon incident with concrete artifacts: two dated disclosures, 583 confirmed targeted rental-server accounts, a 1,360,563-account potential envelope, engaged external forensics, authority reporting and individual customer notification. The score is held below high because the large number is explicitly a bound rather than a confirmed-impact count and no exfiltration or downstream misuse has been established.
Mildly overstated: an upper bound read as exposure
Coverage hedges with 'up to' and 'potential', but the 1,360,563 figure — which the vendor labels explicitly as not a confirmed-impact count — functions as the headline exposure number across the cluster, and the secondary reporting also firms Sakura's 'before August 9' language into an August 9 access or discovery date and widens the password and card-data caveats beyond the vendor's wording. The drift is modest and directional rather than fabricated, so the gap is small and positive.
Vendor-controlled facts plus a commercially sponsored channel
Nearly every substantive fact originates with the affected company, which has clear reasons to emphasize hashed passwords, absent card data, system separation and unconfirmed exfiltration while root cause stays open, and which had not answered press questions. On the reporting side the BleepingComputer item ends with a promotional block for a vendor security report, and SC Media republishes that account without independent checks, so distribution incentives are visible in the sources themselves.
High on disclosed facts, low on cause and final scope
The disclosed facts, figures and response steps are well attested by a primary document plus corroborating coverage, so the story's core is reliable. Confidence is reduced by three unresolved items the sources acknowledge: the contested August 9 timeline, the unidentified malware and initial access vector, and the still-open determination of how many of the 1,360,563 accounts were actually touched.
security
Prevention back to 69%, and a 91-point gap inside one technique1 distinct publisher
build
A UDP packet is now enough: IKEEXT RCE moves from patch queue to fire drill1 distinct publisher
security
California's AI security push is really a hiring order: one AI cyber officer per agency1 distinct publisher
build
A 14,000-star watermark remover, and no detector to test it against1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 19, 2026
1 article · August 20, 2026
1 article · August 20, 2026