Japanese cloud and data center provider Sakura Internet is investigating a cybersecurity incident that may have exposed information associated with more than 1.36 million customer accounts. Attackers gained unauthorized access to the company’s sales management system, which contains membership and contract information.

 

 

Sakura Internet disclosed that its investigation currently covers as many as 1,360,563 potentially affected accounts. However, the company has not established the final number and has not confirmed that information was successfully extracted from the compromised environment.

The unauthorized access occurred on August 9 and was uncovered while Sakura Internet was examining a separate incident involving its Sakura Rental Server service. That investigation revealed unauthorized logins involving 583 accounts, access to customer-facing systems and customer information, as well as malware installed within the company’s environment.

Sakura Internet responded by invalidating credentials associated with the unauthorized activity and removing the detected malware. The subsequent discovery that attackers had reached the sales management system substantially increased the potential scope of the incident.

Although the system contains customer-related information, Sakura Internet said it does not store credit card details. Passwords held within the affected environment are hashed rather than stored as plaintext. The company has not disclosed exactly which categories of customer and contract information may have been accessed.

Sakura Internet has also confirmed that the incident was not ransomware-related. No ransom demand was received, and the company has declined to provide further technical information about the malware involved because of security considerations.

The incident has not been reported to have caused operational or service disruptions. Sakura Internet provides web hosting, virtual private servers, public cloud infrastructure, data center services, and GPU computing. The company also has a strategic role in Japan’s domestic cloud infrastructure after being selected as a provider for the country’s Government Cloud program.

Relevant authorities have been notified, and Sakura Internet is contacting affected customers individually. Its forensic investigation remains underway to determine the precise scope of the unauthorized access.

For now, the figure of 1,360,563 should be treated as the maximum number of potentially affected accounts rather than confirmed victims of data theft. Sakura Internet has not confirmed data exfiltration, and the exact number of accounts whose information was accessed remains under investigation.

Leave a Reply