Sakura Internet disclosed that attackers accessed its sales management system, potentially exposing customer contract and membership information tied to as many as 1,360,563 member accounts. The intrusion was uncovered during an investigation into a separate breach affecting the Sakura Rental Server service, where 583 accounts experienced unauthorized logins and malware was found on Sakura systems. The company said the exact number of affected accounts is still under investigation and that it has not confirmed any data exfiltration.
Sakura said passwords in the affected system were stored in hashed form and that the compromised environment did not contain credit card data. The company also stated the incident was not ransomware-related, no ransom demand was received, and no operational disruption was reported. Sakura invalidated abused credentials, removed detected malware, and notified affected customers and relevant authorities as the investigation continues.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
Sakura Internet said attackers accessed its sales management system, which stored customer contract and membership information. The company identified up to 1,360,563 member accounts as potentially impacted, though the exact number remained under investigation and no data exfiltration had been confirmed.
Sakura Internet publicly disclosed the cyber incident affecting its sales management system and said the intrusion was not tied to ransomware, no ransom demand had been made, and no operational disruption had been reported.
After uncovering the incidents, Sakura Internet said it increased monitoring across its environment and engaged outside forensic specialists to support the investigation. These additional response measures were disclosed alongside its ongoing investigation into the sales management system intrusion and related rental server breach.
Sakura Internet said it informed relevant authorities about the hack and began individually notifying affected customers whose data may have been exposed.
In response to the incidents, Sakura Internet invalidated abused credentials and removed detected malware from affected systems. The company also said the compromised system stored hashed passwords and did not contain credit card information.
During the investigation, Sakura Internet identified a separate breach affecting its Sakura Rental Server service that involved unauthorized logins to 583 accounts, access to customer-facing systems, and malware installation on Sakura systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
6 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcescworld.com
Open sourceteiss.co.uk
Open sourcecyberveille.ch
Open sourcebleepingcomputer.com
Open sourcesakura.ad.jp
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.