Sakura Internet says possible breach exposed data of up to 1.36 million member accounts

Sakura Internet said on August 19 that a third party may have accessed its sales management system, potentially affecting up to 1,360,563 member accounts. The system stores customer contract and member information, and hashed passwords may have been accessed for some users, although the company said it does not store credit card information and has not confirmed data exfiltration. The disclosure followed the company’s August 17 announcement that unauthorized logins occurred across 583 accounts in certain environments of its Sakura Rental Server service. Attackers reached administrative areas of customer accounts, and malware was installed on some servers, creating the possibility that personal data and customer-stored information were viewed or obtained. Sakura Internet believes the sales-system access occurred before the rental-server breach was detected on August 9 and is investigating whether the incidents are connected. The company is revoking authentication credentials, removing malware, strengthening monitoring and conducting forensic work with external specialists. It plans to notify potentially affected users individually. The case is significant because Sakura Internet is one of Japan’s leading rental server providers, serving individuals and corporations, and the suspected extension into a system holding more than 1.36 million member records raises questions about the intrusion route, root cause and the company’s security controls.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.