Sakura Internet, one of Japan’s largest cloud and data-centre providers, disclosed on 17 August 2026 that attackers had logged in to customer environments on its rental-server service, affecting 583 accounts, with access sufficient to install malware. On 20 August it added the larger finding: evidence of possible unauthorised access to a separate sales-management system holding membership and contract data for up to 1,360,563 accounts.
Fields in the sales system include member IDs, names, company and department, addresses, phone numbers, email addresses, birth dates, subscribed services, contract periods and billing amounts. The company reports the attack path blocked, credentials invalidated, malware removed and an external forensic firm engaged. Large-scale exfiltration has not been confirmed, and the reported access to the sales system remains possible rather than established.
From 583 To 1.36 Million In Three Days
The two numbers describe different findings, published three days apart. The first is customer environments attackers demonstrably entered. The second is the population of a system they may have reached. Coverage will quote the larger figure; the honest description is a confirmed small intrusion and a possible large one, and the gap between those will close only as the forensic work completes — the moving-count mechanics recorded at 26-0419.
A Provider’s Own Back Office
The sales-management system is the part of a cloud company that runs on the same ordinary software as any business — CRM, billing, contracts. The corpus keeps finding that the administrative estate around a technical platform is where the customer data pools, and it is rarely defended to the platform’s standard. A hosting customer whose server was untouched may still have their identity and billing details in the affected system, with no action available on their side.
A File The Record Usually Misses
The corpus set out at 25-0502 why incidents outside the Anglophone disclosure economies are underrepresented in every database, including this one. This event reached the English-language record because the company published in detail and kept revising as findings changed — conduct worth naming as the reason the file exists at all.
Compiled from the company’s disclosures as reported and contemporaneous coverage, listed below. The 1.36 million figure is the population of the possibly accessed system, not a confirmed exfiltration count, and the file is graded medium on that basis. Corrections: corrections@forensicpost.com.