← Incident database

sakura-billing-2026 · Disclosed 2026-08-19

Sakura Internet: separate billing-database intrusion

Sakura disclosed billing-database access spanning April 2023 to March 2026 in August 2026, with potential information leakage reported separately from its hosting incident.

Cause unresolved / undisclosedCredentials

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    Billing-database unauthorized access was confirmed without an established link to the hosting incident.

    [s1]2. 請求情報データベース
  • Reported fact

    Potential exposure covers 1,360,563 accounts and some initial passwords, not all current passwords.

    [s1]2. 影響範囲

Timeline

  1. Incident disclosed. [s1]

Reported response

  • Reported fact

    Sakura reported initial-password invalidation or change measures and stronger access control and monitoring.

    [s1]2. 対応 / 3. 再発防止策

Evidence relevant to prevention

Insufficient evidence

The entry cause remains unknown; inspect the need, storage format, retention, and access control for initial credentials.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence.

Intrusion timing is disclosed only by month; account overlap prevents adding the two incident counts.

Sources

  1. [s1] さくらインターネット · Primary source

    当社サービスへの不正アクセスに関するご報告とお詫び(第3報) ↗

    Published 2026-09-10 · Reviewed 2026-10-02