SHINDO1
Rakuten Drive
Rakuten Symphony Korea
Unauthorized accessSize not disclosed
LEAK UNCLEARRecovering
Open in the live monitor ▶- Disclosed
- Jul 30, 2026
- Detected
- Jul 30, 2026 12:55 JST
- Detection to disclosure
- Same day
- Leak
- Unknown
- Type
- Unauthorized access
- Status
- Recovering
- Security spend
- Not checked yet
- Compensation
- Not announced
Not leaked
- No unauthorized third-party access to data stored in Rakuten Drive has been confirmed so far
Who is affected
- Rakuten Drive users
Cause
Suspicious push notifications that appeared to come from Rakuten Drive led users to a fake Google login page and a screen demanding bitcoin (cause not disclosed)
Timeline
- Rakuten Drive posted a warning in its help center
- Around 12:55 on July 30
- Rakuten Mobile announced it
- Service suspended
- Update published
- Service restored
- Rakuten ID passwords of some users were force-reset
Response
- Service stopped
- Password reset
- Hotline
- Phishing warning
Website and help center suspended; dedicated helpline (0800-600-6600); users advised to change Google passwords; passwords of possibly affected Rakuten IDs force-reset
What you should do
- Check the company's notice to see if you're affected
Lessons for companies
- Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
- Run red teaming and AI-assisted hardening, and publish how much you invest
Sources
- piyolog Researcher · Jul 31, 2026