sakura-hosting-2026 · Disclosed 2026-08-17
Sakura Internet: unauthorized management-server access
Sakura disclosed unauthorized access and malware on a hosting management server. Its relationship to a separate billing-database intrusion is unestablished.
Outcome: Confirmed breach
Entry path and evidence
Timeline
Incident disclosed. [s1]
Reported response
- Reported fact
Sakura reported server rebuilding, credential invalidation, and stronger monitoring.
[s1]3. 再発防止策
Evidence relevant to prevention
Insufficient evidence
The entry path is unknown; inspect management exposure, reachable privileges, credential revocation, and detection.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence.
Potential scope is not a confirmed leak count; do not add these accounts to billing-incident counts.
Sources
[s1] さくらインターネット · Primary source
当社サービスへの不正アクセスに関するご報告とお詫び(第3報) ↗Published 2026-09-10 · Reviewed 2026-10-02