Sakura Internet Probes Breach Risk to 1.36 Million Accounts, Finds 30 Hashed Passwords Exposed
Updated
Updated · Bitdefender · Aug 20
Sakura Internet Probes Breach Risk to 1.36 Million Accounts, Finds 30 Hashed Passwords Exposed
3 articles · Updated · Bitdefender · Aug 20
Summary
Up to 1.36 million Sakura Internet accounts may have had personal and contract data exposed after unauthorized access to a sales management system, though the company says that figure is a maximum scope, not confirmed stolen records.
The possible breach surfaced while Sakura investigated an earlier intrusion into its Sakura Rental Server service, which affected 583 accounts, reached customer environments and involved malware on company systems.
Sakura said the sales-system activity occurred before Aug. 9, has not been definitively linked to the rental-server attack, and has shown no evidence so far of large-scale data exfiltration.
Potentially exposed data includes names, contact details, birth dates, subscribed services, contract periods and billing amounts; credit card data was not stored there, and 30 hashed passwords may also have been exposed.
The company has revoked abused credentials, removed malware, tightened monitoring and hired external forensic specialists, while advising customers to change Sakura-related and reused passwords and watch for convincing phishing messages.