← Incident database
rakuten-drive-2026 · Disclosed 2026-10-06
Rakuten Drive: stolen administrator credentials used to access stored data
Illicitly acquired administrator credentials enabled access to stored data and account information. Three events have separate scopes and periods.
Credentials
Outcome: Confirmed breach
Entry path and evidence
Timeline
Reported response
- Reported fact
The path was blocked, monitoring strengthened, and app downloads and new accounts restricted.
[s1]本件への対応
Evidence relevant to prevention
Operational controls to inspect
Inspect administrator-authentication exceptions, credential revocation, data-access scope, and logs.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
AI involvementUnknown
The reviewed disclosures do not establish attacker use of AI.
Credential acquisition and MFA status are undisclosed. Unknown overlap prevents adding the three counts.
Sources
[s1] 楽天ドライブ · Primary source
「楽天ドライブ」における不正アクセスの発生について ↗Published 2026-10-06 · Reviewed 2026-10-09