SHINDO1

Rakuten Drive

Unauthorized accessSize not disclosed

LEAK UNCLEARRecovering

Open in the live monitor ▶
Disclosed
Jul 30, 2026
Detected
Jul 30, 2026 12:55 JST
Detection to disclosure
Same day
Leak
Unknown
Type
Unauthorized access
Status
Recovering
Security spend
Not checked yet
Compensation
Not announced

Not leaked

  • No unauthorized third-party access to data stored in Rakuten Drive has been confirmed so far

Who is affected

  • Rakuten Drive users

Cause

Suspicious push notifications that appeared to come from Rakuten Drive led users to a fake Google login page and a screen demanding bitcoin (cause not disclosed)

Timeline

  1. Rakuten Drive posted a warning in its help center
  2. Around 12:55 on July 30
  3. Rakuten Mobile announced it
  4. Service suspended
  5. Update published
  6. Service restored
  7. Rakuten ID passwords of some users were force-reset

Response

  • Service stopped
  • Password reset
  • Hotline
  • Phishing warning

Website and help center suspended; dedicated helpline (0800-600-6600); users advised to change Google passwords; passwords of possibly affected Rakuten IDs force-reset

What you should do

  1. Check the company's notice to see if you're affected

Lessons for companies

  1. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  2. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources