← Incident database

rakuten-drive-2026 · Disclosed 2026-10-06

Rakuten Drive: stolen administrator credentials used to access stored data

Illicitly acquired administrator credentials enabled access to stored data and account information. Three events have separate scopes and periods.

Credentials

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    Credentials for an administrator account on part of the system were illicitly acquired.

    [s1]概要
  • Reported fact

    August 27 events affected 687 accounts and 313 accounts including transformed passwords. Stored-data access during January 29–September 17 affected 15,382 accounts.

    [s1]事象①〜③

Timeline

  1. Start of the reported stored-data access period. [s1]

  2. Two account-information events occurred. [s1]

  3. End of the reported stored-data access period. [s1]

  4. Administrator access and the three scopes disclosed. [s1]

Reported response

  • Reported fact

    The path was blocked, monitoring strengthened, and app downloads and new accounts restricted.

    [s1]本件への対応

Evidence relevant to prevention

Operational controls to inspect

Inspect administrator-authentication exceptions, credential revocation, data-access scope, and logs.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The reviewed disclosures do not establish attacker use of AI.

Credential acquisition and MFA status are undisclosed. Unknown overlap prevents adding the three counts.

Sources

  1. [s1] 楽天ドライブ · Primary source

    「楽天ドライブ」における不正アクセスの発生について ↗

    Published 2026-10-06 · Reviewed 2026-10-09