Sakura Internet data incident August 2026: 1.36 million accounts, what to know
If you received a notice from Sakura Internet, here’s what the filing says was exposed, and what to do about it.
On 19 August 2026, Sakura Internet confirmed possible unauthorized access to a sales-management system that holds data on up to 1,360,563 member accounts. Names, addresses, phone numbers, emails, dates of birth and contract details may be involved; the company does not store credit-card data and has not confirmed that any information left its systems.
On 19 August 2026, Sakura Internet published a second official report — and a Tokyo Stock Exchange filing the same day — saying it had found possible unauthorized access to a sales-management system that stores customer contract and membership data. That access took place before 9 August 2026, when the company first detected a separate break-in on its rental-server service (disclosed on 17 August, involving 583 accounts and malware). Whether the two events are connected is still under investigation.
Sakura put the possible reach at 1,360,563 member accounts. That number is the total size of the system, including the earlier 583, not a confirmed count of records that were viewed or copied. Fields that may have been involved include member ID, name, address, telephone number, e-mail address, date of birth, gender, company name, department, fax number, contracted services, contract period and billed amounts. The company does not store credit-card data. Hashed password data for 30 accounts may also have been accessed. No data has been confirmed as taken out of Sakura’s systems. Outside specialists are examining what happened; the company says it has reported the matter to Japan’s Ministry of Internal Affairs and Communications and the Personal Information Protection Commission.
This is a customer-file problem, not a card-and-password problem
Most accounts of this incident will lead with three true sentences: Sakura does not keep card numbers; only a small number of hashed passwords may have been touched; and the company has not found evidence that anything was copied out. Those lines sound like a sigh of relief. They are the least useful part of the story if you are trying to work out whether this is about you.
The 17 August notice was about 583 rental-server accounts and malware on those machines. If you do not rent one of those servers, it is natural to stop there. The 19 August report is about a different room: the sales system that holds membership and contract records. Sakura’s own figure for that system is up to 1.36 million accounts. Cloud, VPS, dedicated-server and other contracted customers sit in that file. So do the original 583. This is not “the server incident, plus a few extra people.”
What that file contains, if it was read, is not a pile of passwords or payment cards. It is who the customer is and how to reach them — name, home address, phone, email, date of birth, gender, company — plus what they bought and what they were billed. Nobody needs a card number to use that. It is enough to send a message that already knows your contract, or to match a name and address to the rest of the public internet.
Sakura is not saying this file was emptied. It is saying someone may have been inside the system that holds it, before the first incident was even detected, and that it still does not know which records were viewed or whether any were copied. “No data has been confirmed leaving” is a statement about what they have found so far. It is not a finding that your record was left alone.
What to actually expect
- Sakura says it is notifying individual customers as the investigation proceeds. Watch for a message that comes through a channel you already use with them. Silence is not a result; the company still does not know the precise number of affected records.
- Expect copycat emails, chats or calls that mention this incident, a membership, or a billed amount and then ask you to sign in, “verify” a contract, or pay a fee. Treat those as hostile unless you reached Sakura yourself through a number or site you already trust.
- Password resets apply where Sakura is revoking access. Hashed password data is described as a possible issue for 30 accounts, not for the 1.36 million. Unless Sakura tells you that you are in that group, this incident is not itself evidence your password was taken.
- At the time of the first report, Sakura said its cloud, VPS and dedicated-server services showed no impact. That is about those machines, not about whether your membership record sat in the sales system.
What you can and cannot fix
If a name, home address, telephone number, email address, date of birth, gender, company or department, or contract and billing history was copied, that copy cannot be pulled back. Those facts do not expire, and there is no recall. Sakura has not confirmed that this happened. If it did, it cannot be undone. There is also no reliable public check that can tell you whether your own row was touched — and a “clean” result from any such check would not mean you were absent from this system.
What still helps, in order:
- Use Sakura’s 19 August report, its support and FAQ pages, and any notice addressed to you. Act on those. Do not act on forwards, “security alerts,” or strangers reciting the news.
- If Sakura asks you to reset a password or review access, do it on the site or app you already use — not from a link in a new message.
- For the near term, treat any unexpected contact that already knows your Sakura contract, billed amount, or personal details as a reason to stop, then check through a channel you already have.
- Reduce the public listings that make a leaked name and address dangerous. A bare membership record becomes much more useful once it is joined to people-search and data-broker pages that add relatives, extra phone numbers, employers and previous addresses. Those listings, unlike anything already copied from Sakura, can actually be removed. That is the lever that is still in your hands.
Report details & sourcing
Related breaches
Brightspeed Fiber Broadband Incident — January 2026
Crimson Collective ransomware group allegedly stole personal data of over 1 million Brightspeed cust…
Figure Technology Solutions 967K Accounts — February 2026
Lending and home-equity tech firm Figure Technology Solutions disclosed a social-engineering breach …
Was I in the SafePal data breach? What they took and what they didn't
On 16 August 2026 SafePal said a flaw in its order-tracking plug-in exposed names, emails, shipping …