SOCLYDE logo
Current languageEN
Cybersecurity newsHostingIntrusionData breach

Sakura internet: 951 hosting accounts enter the scope of an intrusion

Sakura Internet’s third report covers unauthorized access to hosting environments and a sales system, without confirming equivalent data exfiltration.

By Soclyde Team

An IT operations building entrance inspected at dusk

In summary

  • Sakura Internet published a third report on unauthorized access detected in August.
  • 951 Sakura Rental Server accounts may be in scope, while the sales system contains 1,360,563 records.
  • The report distinguishes possible access from confirmed data exfiltration.

Explore next

Soclyde resources

Article contents

On September 10, 2026, Sakura Internet published a third report on unauthorized access detected on August 9 in environments linked to Sakura Rental Server and in its sales-management system.

The report says information from 951 hosting accounts may have been accessible, while the sales system contains 1,360,563 records. Those figures describe possible scope, not a confirmed number of people whose data was exfiltrated.

What Sakura found

Sakura says part of its rental-server environment was accessed without authorization and malware was installed on some servers. It isolated environments, reviewed access and engaged external specialists.

The sales system was also involved. Sakura says it found no clear evidence of data leaving the environment or secondary harm attributable to the incident at the time of the report.

Why the scope changed

The hosting-account count rose from 583 in an earlier notice to 951 after additional checks. This shows why supplier incidents can take time to qualify when many logs and environments are involved.

A potentially affected account is not the same as a confirmed victim. It still justifies notification, checking and cautious secret rotation.

Checks for a hosted website

Review administrator accounts, recently changed files, scheduled tasks, redirects, mail accounts and login logs. Look for changes your team cannot explain.

Do not download a supposed remediation tool from an email. Use Sakura’s customer portal or official website, and preserve useful evidence before restoring a compromised site.

The risk of reused secrets

A password copied across hosting, a CMS and email increases the impact of a limited access event. Rotation should cover actual accounts, API keys and administrator access.

The Soclyde connection

Soclyde cannot replace provider controls or prove a website’s integrity. It helps keep separate secrets for hosting, the CMS and email in an encrypted vault that makes rotation easier after a supplier alert.

Takeaway

Sakura Internet places 951 hosting accounts and a 1,360,563-record sales system within possible scope, without confirming equivalent exfiltration. Customers should review access, preserve evidence and eliminate reused secrets.

Read our team password sharing guide · Contact Soclyde

Frequently asked questions

Were all 1,360,563 records stolen?

No. Sakura says the sales system may have been accessed, but it does not confirm that all of those records left the environment.

What should a hosted customer check?

Review administrator accounts, files, scheduled tasks, logs and unusual mail activity, and follow Sakura’s official notices.

Should passwords be changed?

Change any secret that was reused, stored in an exposed file or used on a potentially affected account, from a clean device.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading