Japanese cloud and data center provider Sakura Internet has significantly expanded the scope of a security incident it first disclosed earlier this week, now saying that up to 1,360,563 member accounts may have been affected.

Sakura Internet is a major digital infrastructure operator in Japan, offering web hosting, VPS, public cloud, data center, and GPU computing services. The company has also been selected as a domestic provider for Japan’s Government Cloud program, giving it a strategic role in reducing the country’s reliance on foreign hyperscalers.

According to the company’s updated notification, attackers first accessed its IT systems on August 9. The intrusion was uncovered while investigators were looking into a separate, smaller breach affecting its Sakura Rental Server service. That earlier incident involved unauthorized logins to 583 accounts, access to customer-facing systems and client data, and malware planted on Sakura’s infrastructure.

While probing that rental server breach, investigators found that hackers had also accessed the company’s sales management system, which stores customer contract and membership information. Data collected so far indicates that as many as 1.36 million accounts could have been exposed, though the company says the exact figure is still being determined as the investigation continues.

  • Sakura says it has invalidated all abused credentials and removed the malware from its systems
  • No data exfiltration has been confirmed at this stage
  • Stored passwords are hashed, which the company says makes them difficult to decipher if stolen
  • The affected system does not store credit card information
  • No operational or service disruptions have been reported

Sakura has notified relevant Japanese authorities and says it is individually contacting affected customers. It remains unclear what type of malware was used in the attack. No ransomware or data extortion group has publicly claimed responsibility for the breach so far.

Given Sakura’s role in Japan’s Government Cloud initiative, the incident underscores the risk that lateral discovery during breach investigations can reveal, where a seemingly contained compromise turns out to be a foothold into far more sensitive systems. Organizations running similar sales or customer management platforms should treat any confirmed unauthorized access as a trigger for a broader environment-wide review, not just remediation of the initially identified system.