On 9 August 2026, hackers gained access to internal IT systems at Sakura Internet Inc. (Sakura Internet), a major Japanese provider of web hosting, VPS, public cloud, data centre and GPU computing services and a designated domestic provider for Japan's Government Cloud programme. The company did not discover the intrusion at the time. It surfaced only during the investigation of a separate, smaller incident: unauthorised logins to 583 accounts on its Rental Server service, where attackers had also installed malware and accessed customer-facing systems and client data.
That smaller investigation led straight into a bigger one. Sakura found that the same access had reached its sales management system, the internal platform storing customer contract and membership records. In an update issued on 19 August, ten days after the initial intrusion, the company said up to 1,360,563 member accounts may have been affected. Stored passwords were hashed, no credit card data was held in the system, and Sakura says it has invalidated the abused credentials and removed the malware it found.
What Sakura has not said is how the attacker moved from 583 compromised Rental Server accounts to a system holding well over a million more records. No ransomware group or extortion gang has claimed the attack, and the company has confirmed there was no ransom demand. That absence of a claim is not reassurance. It means the access that mattered here, the pivot from one compromised system into another with a much larger blast radius, happened without a single external voice announcing it, and might never have surfaced at all if a smaller, unrelated breach had not forced a closer look.
The scale puts Sakura among the larger disclosed breaches in Japan this year, and its position in the Government Cloud programme raises the stakes further. This is not an isolated pattern. Across 2026, a string of breaches, from healthcare administrators to logistics providers to CRM platforms, have shared the same structure: an attacker's initial foothold, however small, becomes a springboard into a much larger internal system that nobody had separately gated.
The defences that failed here were not weak by conventional standards. Sakura hashed its passwords, segmented its credit card data out of the exposed system, invalidated compromised credentials once found, and disclosed proactively to regulators and customers. None of that stopped the initial pivot from a rental server credential compromise into a sales management system holding over a million accounts. The gap sat at the boundary between those two systems, where access from one apparently qualified an attacker to reach the other.
A pivot from one internal system into another that holds thirteen hundred thousand customer records is an execution event, not a background permission check. Before an account or session that touched the Rental Server environment can reach the sales management system, a confirmation request should go to the named system owner on their registered device. The request does not depend on whether the credentials presented are technically valid within the environment. It depends on whether a named human authorised this specific system, this specific access, right now.
A set of stolen or reused credentials, however cleanly they pass authentication, cannot produce that confirmation on a device the attacker does not hold. The execution boundary holds regardless of which internal system the request appears to come from.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence and governance network for Security, Resilience & Defence teams.
References
1. Toulas, B. 2026. Sakura Internet hack exposes data of up to 1.36 million accounts. BleepingComputer, 19 August 2026.
2. Bartram, N. 2026. Data Breach Roundup (August 14 - 20, 2026). Privacy Guides, 21 August 2026.
Back to Blog
Case Studies·3 min read
How did investigating 583 stolen logins at Sakura Internet uncover a door into 1.36 million more accounts?
By GoFirm
