Sakura Internet, a Japanese cloud and data-center services provider, disclosed that hackers accessed a sales management system containing customer contract and membership information, according to BleepingComputer. The company said in an update that up to 1,360,563 member accounts may have been affected, though the final number is still under investigation. The reported access occurred on August 9. BleepingComputer says Sakura discovered the larger incident while investigating a separate breach involving its Sakura Rental Server service. That separate rental-server incident was smaller in account count but still operationally significant. According to the report, it involved unauthorized logins to 583 accounts, access to customer-facing systems and client data, and malware installed on Sakura’s systems. Sakura said it invalidated abused credentials and removed the malware. The newly disclosed exposure raises the stakes because the accessed sales management system held contract and membership information. Sakura said its investigation so far indicates 1,360,563 accounts were potentially compromised, but it has not confirmed data exfiltration. The company also said stored passwords were hashed and should be difficult to decipher if stolen, according to BleepingComputer. Sakura specified that the compromised system did not store credit card information. Sakura has notified relevant authorities and is individually informing affected customers about the exposure. BleepingComputer reported that Sakura did not mention operational or service disruptions, and the outlet said it found no ransomware or data-extortion group publicly claiming responsibility for the attack. The company’s role makes the incident more sensitive than a routine hosting-provider breach. BleepingComputer describes Sakura Internet as a major Japanese digital infrastructure company offering web hosting, virtual private servers, public cloud, data-center services, and GPU computing, and says it has been selected as a domestic provider for Japan’s Government Cloud program. Who benefits: Affected customers benefit from direct notification and from Sakura’s reported invalidation of abused credentials in the related rental-server incident. Security teams get a clearer prompt to review account access tied to Sakura services. Who's exposed: The exposed group is Sakura member accounts whose contract or membership information was stored in the accessed sales management system. Sakura’s broader role in Japanese cloud and data-center infrastructure increases scrutiny of how fully the company can determine scope and containment.