Japanese cloud computing and data center services provider Sakura Internet recently issued a security advisory disclosing that attackers breached its customer management system on August 9, 2026. That system stores contract agreements and various categories of personal and corporate information for roughly 1.36 million customers.
Sakura Internet stands among Japan’s major digital infrastructure providers, offering website hosting, VPS servers, public cloud, data center, and GPU computing services. The company also holds a place among the domestic vendors selected for Japan’s government cloud initiative, helping the Japanese government maintain digital sovereignty in the cloud computing space.
Approximately 1.36 Million Customers Affected
Sakura Internet first noticed anomalies within its customer management system while investigating a separate security incident affecting its Sakura Rental Server service. According to preliminary investigation findings, 583 accounts experienced unauthorized logins, attackers accessed customer-facing systems and customer data, and attackers installed malware on Sakura Internet’s systems.
Upon discovering the anomaly, Sakura Internet’s security team immediately removed the malware and rotated every credential that could potentially have been exposed. However, as the investigation deepened, the number of affected customers proved considerably larger than initially believed. Based on evidence gathered during the subsequent investigation, as many as 1,360,563 accounts may have been affected – though no confirmed instance of actual data exfiltration has occurred at this stage.
That said, Sakura Internet never stored passwords in plaintext, so even if attackers managed to steal the underlying data, they would only obtain hashed and salted passwords. Cracking such passwords is far from trivial, meaning attackers should currently have no practical way to use the stolen hashed credentials to log into customer accounts.
Data Theft Without a Ransom Demand
Notably, no hacking group has claimed responsibility for the incident so far. In a typical ransomware attack, attackers usually publicize the breach on their own dark web leak site and demand a ransom from the affected company once they’ve succeeded. In this case, however, no group has come forward demanding payment.
Sakura Internet’s official statement confirmed that this attack is indeed unrelated to ransomware. The company stated: “We have confirmed that this incident is unrelated to ransomware and does not involve any ransom demand. However, for security reasons, we are currently unable to disclose further details regarding the malware involved.”
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.