SHINDO5

SAKURA internet

Personal data1.4Maccounts

POSSIBLE LEAKPassword / Postal addressUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Aug 17, 2026
Detected
Aug 9, 2026
Detection to disclosure
8 days
Leak
Leak possible
Type
Unauthorized access
Status
Contained
Security spend
Measures, no amount
Compensation
Not announced
Corporate number
3120001079845

What leaked

Account dataMember ID
Business dataCompany name
Employment & HRDepartment name
ContactAddress, Phone and fax numbers, Email address
IdentityFull name, Date of birth, Gender
Transactions & activityContracted services and contract period
Financial & paymentBilled amount
CredentialsHashed member-ID password information (30 accounts), Initial server passwords and email passwords
Communications & contentEmail data, Website data, logs and other files stored in customers' areas

Not leaked

  • SAKURA does not hold credit card information, so no card information was leaked

How many

  • Member records in the sales management system 1.4M accounts
  • SAKURA Rental Server accounts with unauthorized logins 951 accounts
  • Accounts whose hashed passwords may have been viewed 30 accounts

Who is affected

  • Members
  • Corporate customers (company and department names)

Cause

A third party went through SAKURA's own management environment (a maintenance server) into customer environments and planted malware on some servers; the sales management system had also been accessed since April 2023. Technical details not disclosed

Timeline

  1. Unauthorized access to the sales management system
  2. Unauthorized access to the sales management system
  3. Detected
  4. Contained
  5. Reported to authority
  6. Reported to authority
  7. First disclosure
  8. Disclosed unauthorized access to the sales management system
  9. Investigation results and prevention measures; 1,360,563 accounts affected

Response

  • Revoked credentials
  • Blocked the entry point
  • Forensic investigation
  • Access review
  • New detection
  • External audit
  • Staff training
  • Notified individuals
  • Hotline

Revoked credentials and blocked access; removed malware and ran a forensic investigation; full review and tightening of administrator privileges; wider EDR coverage; review of authentication methods. Planned: rebuild all servers, regular external audits, more security training. Dedicated line 0120-378-719

What you should do

  1. Change this password and every account that reused it now. Weak passwords crack even when hashed or encrypted. Switch to a passkey where offered
  2. Don't open links in emails from this company. The apology email itself may be fake
  3. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  4. Watch for unexpected mail or invoices; your address is hard to change
  5. Check the company's notice to see if you're affected

Lessons for companies

  1. Don't keep ID or bank data: delete after checks or use a KYC provider
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources