The Hosting Systems Were Separate. 1.36 Million Customer Accounts Were Still in Scope.
Sakura Internet began with an intrusion into a limited set of rented-server accounts. The investigation then found possible unauthorised access to a separate sales-management system that placed 1,360,563 customer accounts within the potential impact scope.
The Japanese hosting and cloud provider said the larger number is not a confirmed count of compromised accounts. As of its 19 August 2026 update, Sakura had not confirmed that data from the sales system was taken outside the company. It had, however, established that a third party may have viewed or acquired customer information and may have accessed hashed passwords belonging to some customers.
The incident illustrates a common breach pattern. A company can isolate production platforms from corporate administration systems and still face a large customer-data event. Separating the service environment protects workload availability. It does not make the contract, billing, support, and identity systems unimportant.
The first confirmed scope was 583 accounts
Sakura disclosed on 17 August that attackers had logged into 583 accounts in parts of its Sakura Rental Server service. The intruder reached areas available to those customer accounts, installed malware, and may have viewed or obtained personal information contained in some customer environments.
The company invalidated credentials used in the unauthorised access, blocked access, removed malware, and strengthened monitoring. It continued investigating the affected systems and brought in external specialists for forensic analysis.
That initial incident was already operationally important. A hosting account can contain websites, email, databases, application secrets, and customer data. Malware on a hosted environment can support phishing, web skimming, credential theft, malicious redirects, or attacks on visitors.
The larger disclosure came from the work performed after containment. Sakura found possible unauthorised access to the sales-management system used to administer contracts and customer information. The company said that event occurred before 9 August, when it detected the rented-server intrusion. It was still investigating whether the two events were related.
A separate system held the larger blast radius
Sakura emphasised that the sales-management system is separate from the environments that deliver services such as Sakura Cloud. That is a useful security boundary. It means the disclosure does not establish that customer cloud workloads, every hosted server, or the provider’s whole production platform was compromised.
The separation also explains why the incident should not be summarised as a single hosting-platform breach. Two scopes are under investigation: confirmed unauthorised access affecting 583 rented-server accounts, and possible earlier access to a business system containing information associated with as many as 1,360,563 accounts.
The second system can be more consequential for privacy even though it is not the core hosting platform. Sales and contract systems often concentrate names, contact details, account identifiers, service relationships, and authentication records across the entire customer base.
Sakura said some hashed password information in the sales-management system may have been accessible. A password hash is not the original password, and a strong modern hashing scheme makes recovery difficult. Risk still depends on the algorithm, work factor, salts, password quality, and the attacker’s computing resources. The company had not publicly established that hashes were taken.
Sakura also said it does not store credit-card information in the affected system. That removes one category of direct financial exposure, but it does not eliminate phishing, account-recovery abuse, password reuse, or impersonation risks.
Potentially affected is not the same as stolen
The wording of the primary disclosure requires precision. The 1,360,563 figure represents customer accounts that may be affected because their information was stored in the system under investigation. It is not a verified exfiltration count.
Sakura had not confirmed an external transfer of data from the sales-management system as of 19 August. Absence of confirmed exfiltration is not proof that no data left. It means forensic analysis had not produced that conclusion at the time of the update.
BlackTree is therefore treating the figure as the maximum current exposure scope, not as a claim that 1.36 million customer records were stolen. Future updates may narrow the affected population, confirm particular fields, or establish whether the two intrusions share a cause.
This distinction matters for defenders and customers. Overstating the evidence creates unnecessary alarm. Understating the potential scope can delay password changes, fraud monitoring, and investigation of hosted systems.
What Sakura customers should do
Customers who receive an individual notice should follow the provider’s instructions and verify the message through Sakura’s official website or support channel. Attackers frequently exploit the period after a public breach by sending realistic password-reset and account-verification messages.
Customers should change Sakura credentials if instructed and replace any password reused on another service. Reuse is dangerous because even a well-protected hash can become useful if a weak password is eventually recovered or if the same credential appeared in another breach.
Rented-server customers should inspect their own environments for unauthorised files, altered web content, new administrative users, malicious scheduled jobs, unexpected outbound traffic, and changes to application or domain settings. Provider-level containment cannot determine every action performed inside an individual customer’s reachable space.
Organisations should preserve logs before rebuilding or cleaning systems. Web, authentication, file-integrity, mail, database, and control-panel records can show whether the account was used to access data, modify a site, or distribute malware.
Users should be sceptical of messages that cite a real Sakura account, service name, or contract relationship. Correct context may come from exposed business data. It does not prove that the sender is Sakura.
The investigation needs to connect identities and systems
Sakura said it was invalidating abused credentials, removing malware, strengthening monitoring, confirming the scope of the sales system, conducting an external forensic investigation, reporting to relevant bodies, and notifying affected customers.
A central question is how credentials used against rented-server accounts relate to the possible access to the sales-management system. Shared identity infrastructure, reused credentials, support tooling, administrative workstations, and account-recovery channels can create connections between systems that are technically hosted in separate environments.
Investigators also need to determine whether the sales-system access was exploratory or whether records were queried in bulk, whether password hashes were merely reachable or actually read, and whether the malware found in customer environments supported persistence, collection, or movement toward other Sakura services.
For other cloud and hosting providers, the defensive lesson is broader than network segmentation. Customer identity and contract systems deserve controls proportionate to the number of accounts they aggregate: phishing-resistant administrator authentication, narrowly scoped service identities, independent logging, export detection, session monitoring, and tested separation from support and production access paths.
Separate platforms can still share one incident
Sakura’s service platforms and its sales-management system were separate. That separation appears to have prevented the company from equating possible access to customer records with a compromise of Sakura Cloud. It did not prevent the investigation from expanding from 583 accounts to a potential population of more than 1.36 million.
The distinction captures why breach scoping is often difficult. Technical isolation can limit direct movement while common identities, customers, staff, and operational processes still connect the systems. The first detected environment may not contain the largest dataset at risk.
Sakura customers should treat the current disclosure as an active investigation. Respond to individual notifications, secure reused credentials, examine hosted environments, and watch for convincing account-related phishing. The most important unanswered question remains whether access to the sales-management system resulted in data leaving the company.


