Sakura Internet Hack Affects 1.36 Million Accounts
Sakura Internet, a leading cloud and data center provider in Japan, has disclosed a major cyberattack that could affect up to 1.36 million customer accounts. Attackers are said to have breached the company's sales management system.
What Happened
Sakura Internet, one of Japan's largest digital infrastructure companies and a strategic partner in the nation's government cloud program, has become the target of cyberattackers. According to a statement from the company, attackers gained unauthorized access to its sales management system, where customer contract and membership information is stored.
The incident was first discovered during an investigation into a smaller security breach at a different service, Sakura Rental Server. In that initial incident, 583 accounts were accessed without authorization, customer data was reached, and malware was installed on the company's systems. However, as this investigation deepened, a much larger security vulnerability was identified.
In an update today to its initial notification from Monday, the company announced that up to 1,360,563 member accounts may have been potentially affected by the attack. It was emphasized that the exact number of affected accounts is still unconfirmed as the investigation is ongoing.
Data Compromised
The system accessed by the attackers contained customer contract details and membership information. Sakura Internet shared some important details about the nature of the compromised data. According to the announcement, the passwords stored in the system were hashed. This means that even if the passwords were stolen, they would be very difficult to crack. Hashing protects data by converting it into a meaningless string of characters through a one-way algorithm.
The company also confirmed that no credit card information was stored in the compromised system. This significantly reduces the risk of financial fraud. However, data such as membership information and contract details could potentially be used for phishing attacks. It was stated that there is currently no definitive evidence of data exfiltration, but this possibility is being investigated.
How Did the Attack Happen
According to the company's statement, the attackers first gained access to its IT systems on August 9. The discovery of this breach occurred thanks to the investigation into the previous incident at Sakura Rental Server, which affected 583 accounts. The company stated that it had invalidated all abused credentials and removed the malware installed in the initial incident. However, no technical details about the type of malware or the attack vector were shared.
It is not yet clear whether this larger breach is directly related to the first incident or if it was carried out by the same attackers. BleepingComputer also reported that no ransomware or data extortion group has claimed responsibility for the attack.
Who Is Affected
Those potentially affected by the attack are the customers of Sakura Internet, with up to 1,360,563 member accounts. Sakura Internet is of strategic importance not only for the private sector but also as one of the domestic providers selected for Japan's national "Government Cloud" program. This role aims to reduce the country's dependence on foreign technology giants. Therefore, this attack concerns not only individual users and companies but also has implications for the security of the national digital infrastructure.
What You Can Do
Sakura Internet has announced that it has begun the process of notifying affected customers individually. If you are a Sakura Internet customer, you should carefully follow official announcements from the company.
- Wait for Official Communication: Wait for notifications from the company via email or your account dashboard.
- Be Wary of Phishing Attacks: Attackers may use the compromised information to target you with fake emails that appear to be from Sakura Internet. These emails may ask for your password, credit card information, or other personal data. Do not click on suspicious links or share your personal information.
- Password Security: Although Sakura Internet states that passwords were hashed, if you use the same password on different platforms, it is recommended as a general security measure to change your passwords on other accounts.
What the Company Says
Sakura Internet stated that it informed the relevant government authorities immediately after the incident. The company emphasized that the investigation is ongoing and they are working to determine the exact number of affected accounts. The announcement did not mention any operational service disruptions. The company stated that it is taking the necessary steps to ensure the security of customer data and is conducting a transparent communication process. BleepingComputer reported that its request for additional information has not yet received a response.
Source
This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.