← Incident database

sakura-hosting-2026 · Disclosed 2026-08-17

Sakura Internet: unauthorized management-server access

Sakura disclosed unauthorized access and malware on a hosting management server. Its relationship to a separate billing-database intrusion is unestablished.

Cause unresolved / undisclosed

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    Unauthorized access and malware were confirmed following an August 9 anomaly.

    [s1]1. ホスティングサービス
  • Reported fact

    The potentially affected scope is 951 accounts, including 368 without a clear established intrusion link.

    [s1]1. 影響範囲

Timeline

  1. Incident disclosed. [s1]

Reported response

  • Reported fact

    Sakura reported server rebuilding, credential invalidation, and stronger monitoring.

    [s1]3. 再発防止策

Evidence relevant to prevention

Insufficient evidence

The entry path is unknown; inspect management exposure, reachable privileges, credential revocation, and detection.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence.

Potential scope is not a confirmed leak count; do not add these accounts to billing-incident counts.

Sources

  1. [s1] さくらインターネット · Primary source

    当社サービスへの不正アクセスに関するご報告とお詫び(第3報) ↗

    Published 2026-09-10 · Reviewed 2026-10-02