On 19 August 2026, Sakura Internet published a second official report — and a Tokyo Stock Exchange filing the same day — saying it had found possible unauthorized access to a sales-management system that stores customer contract and membership data. That access took place before 9 August 2026, when the company first detected a separate break-in on its rental-server service (disclosed on 17 August, involving 583 accounts and malware). Whether the two events are connected is still under investigation.
Sakura put the possible reach at 1,360,563 member accounts. That number is the total size of the system, including the earlier 583, not a confirmed count of records that were viewed or copied. Fields that may have been involved include member ID, name, address, telephone number, e-mail address, date of birth, gender, company name, department, fax number, contracted services, contract period and billed amounts. The company does not store credit-card data. Hashed password data for 30 accounts may also have been accessed. No data has been confirmed as taken out of Sakura’s systems. Outside specialists are examining what happened; the company says it has reported the matter to Japan’s Ministry of Internal Affairs and Communications and the Personal Information Protection Commission.
This is a customer-file problem, not a card-and-password problem
Most accounts of this incident will lead with three true sentences: Sakura does not keep card numbers; only a small number of hashed passwords may have been touched; and the company has not found evidence that anything was copied out. Those lines sound like a sigh of relief. They are the least useful part of the story if you are trying to work out whether this is about you.
The 17 August notice was about 583 rental-server accounts and malware on those machines. If you do not rent one of those servers, it is natural to stop there. The 19 August report is about a different room: the sales system that holds membership and contract records. Sakura’s own figure for that system is up to 1.36 million accounts. Cloud, VPS, dedicated-server and other contracted customers sit in that file. So do the original 583. This is not “the server incident, plus a few extra people.”