Desk live·
ForensicPost
Cloud/SaaS/File 26-0820b

Sakura Internet Says Up to 1.36 Million Accounts May Be Affected by Two Linked Intrusions

Japan’s Sakura Internet found attackers in customer rental-server environments on 17 August, then possible access to a sales system holding 1.36 million members’ contract data. Exfiltration is unconfirmed, and the file is graded accordingly.

Constructed geometry · not a chart of case data
JurisdictionJapanOsakathe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetSakura Internet
ActorUnattributed
S. Rosler10 min readConfidence: medium3 sources reviewed

Sakura Internet, one of Japan’s largest cloud and data-centre providers, disclosed on 17 August 2026 that attackers had logged in to customer environments on its rental-server service, affecting 583 accounts, with access sufficient to install malware. On 20 August it added the larger finding: evidence of possible unauthorised access to a separate sales-management system holding membership and contract data for up to 1,360,563 accounts.

Fields in the sales system include member IDs, names, company and department, addresses, phone numbers, email addresses, birth dates, subscribed services, contract periods and billing amounts. The company reports the attack path blocked, credentials invalidated, malware removed and an external forensic firm engaged. Large-scale exfiltration has not been confirmed, and the reported access to the sales system remains possible rather than established.

From 583 To 1.36 Million In Three Days

The two numbers describe different findings, published three days apart. The first is customer environments attackers demonstrably entered. The second is the population of a system they may have reached. Coverage will quote the larger figure; the honest description is a confirmed small intrusion and a possible large one, and the gap between those will close only as the forensic work completes — the moving-count mechanics recorded at 26-0419.

A Provider’s Own Back Office

The sales-management system is the part of a cloud company that runs on the same ordinary software as any business — CRM, billing, contracts. The corpus keeps finding that the administrative estate around a technical platform is where the customer data pools, and it is rarely defended to the platform’s standard. A hosting customer whose server was untouched may still have their identity and billing details in the affected system, with no action available on their side.

A File The Record Usually Misses

The corpus set out at 25-0502 why incidents outside the Anglophone disclosure economies are underrepresented in every database, including this one. This event reached the English-language record because the company published in detail and kept revising as findings changed — conduct worth naming as the reason the file exists at all.

How we reported this

Compiled from the company’s disclosures as reported and contemporaneous coverage, listed below. The 1.36 million figure is the population of the possibly accessed system, not a confirmed exfiltration count, and the file is graded medium on that basis. Corrections: corrections@forensicpost.com.

Sources
  1. Sakura Internet hack exposes data of up to 1.36 million accountsBleepingComputer
  2. Japanese cloud provider Sakura Internet discloses breach affecting 1.36 million membersteiss
  3. Sakura Internet hack may affect 1.36 million accountsBitdefender
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary