Translating into Русский. The English version is shown until it is ready.
Rakuten Drive says unauthorized access exposed data from 15,382 accounts
Коротко
Rakuten Drive, a cloud storage service, said part of its systems was accessed without authorization and that stored data from 15,382 accounts — including photos and documents — was obtained or viewed between January 29 and September 17, 2026. The company said information from 687 accounts, and encrypted passwords from 313 of them, was also accessed on August 27. It said it has blocked the access route, restricted app downloads and new account creation, reported to authorities, and found no secondary damage so far.
Читать полностью 2 мин чтения
Rakuten Drive, a cloud storage service, said on October 6 that part of the systems it uses was accessed without authorization, after a third party improperly obtained the credentials of a management account and reached the service's internal systems. [ 1 , 2 ]
The largest incident involved data stored on Rakuten Drive itself. The company said it confirmed that stored data, including photos and documents, from 15,382 accounts was obtained or viewed between January 29 and September 17, 2026. [ 1 , 2 ]
A second incident on August 27 involved account names, display names — the nickname shown to other users when files are shared — and profile image URLs from 687 accounts. In 313 of those accounts, the data also included encrypted passwords and strings added at the time of encryption to make restoration difficult. ASCII.jp reported that Rakuten Drive said the passwords had been processed to make them hard to recover. [ 1 , 2 ]
The company said it blocked the unauthorized access route, strengthened its monitoring, and restricted app downloads and the issuance of new accounts, and that it reported the matter to the relevant authorities. It said affected users would be notified individually by email or other means, and that no secondary damage from the access had been confirmed at present. [ 1 , 2 ]
ITmedia reported that the company advised customers who notice logins they do not recognize, anomalies in their accounts, charges they cannot explain, or contact that appears to be a threat or impersonation to consult the service's help desk or the police, and asked them not to open or respond to suspicious messages. [ 2 ]
The documents differ on who operates the service: ASCII.jp described Rakuten Drive as a cloud storage service of the Rakuten Group, while ITmedia said it is provided by Rakuten Mobile. Business outlets Tokyo Shimbun and Nishi-Nippon Shimbun carried short wire items headlined that photos and documents leaked through unauthorized access, and Livedoor News carried a brief item on the same leak. [ 1 , 2 , 3 , 4 , 5 ]
Почему это важно
Stored photos and documents from more than 15,000 accounts were viewed, and encrypted passwords were among the data taken, which the company itself said it is notifying affected users about individually. The restrictions the company placed on app downloads and new account registrations indicate the incident is still being contained rather than fully closed. The documents give no further basis for assessing wider impact beyond the service itself.
Ключевые факты
- Rakuten Drive said some of its systems were accessed without authorization after a management account's credentials were obtained improperly [ 1 , 2 ]
- Stored data including photos and documents from 15,382 accounts was obtained or viewed between January 29 and September 17, 2026 [ 1 , 2 ]
- On August 27, account names, display names and profile image URLs from 687 accounts were obtained or viewed [ 1 , 2 ]
- For 313 accounts, the data also included encrypted passwords and character strings added during encryption to make restoration harder [ 1 , 2 ]
- The company said it blocked the access route, strengthened monitoring, restricted app downloads and new account creation, and reported to authorities [ 1 , 2 ]
- Affected users will be notified individually, and no secondary damage has been confirmed so far, the company said [ 1 , 2 ]
- ITmedia reported the company urged users who notice unrecognized logins, unexplained charges or suspicious contact to consult the service's help desk or police [ 2 ]
Подтверждено несколькими источниками
- Part of Rakuten Drive's systems was accessed without authorization, and stored data including photos and documents was obtained or viewed [ 1 , 2 ]
- Stored data from 1万5382 accounts — 15,382 accounts — was obtained or viewed between January 29 and September 17, 2026 [ 1 , 2 ]
- On August 27, information from 687 accounts was obtained or viewed, and for 313 of them encrypted passwords and accompanying strings were included [ 1 , 2 ]
- The company blocked the access route, strengthened monitoring, restricted app downloads and new account creation, and reported to authorities [ 1 , 2 ]
- Affected users will be notified individually and no secondary damage has been confirmed at present [ 1 , 2 ]
Пока неясно
- Whether the service is operated by Rakuten Group or by Rakuten Mobile ASCII.jp describes Rakuten Drive as a cloud storage service of the Rakuten Group, while ITmedia says it is provided by Rakuten Mobile; the documents do not reconcile this.
- Whether all affected users have already been notified Both documents say users will be notified individually and by email, but do not say whether notification has been completed.
- How the management account credentials were obtained, and who was behind the access The documents attribute the intrusion to a third party obtaining credentials improperly but give no further detail on method or identity.
- The exact scope of the January 29 to September 17 access period for each account The documents give the overall period only, without a breakdown of individual accounts.
Что пишут местные СМИ
Хронология, местное время
- Rakuten Drive announces that part of its systems was accessed without authorization [ 1 ]
- ITmedia reports the breach, including the three incidents, the 15,382-account figure and the containment measures [ 2 ]
- Livedoor News carries a brief item on the unauthorized access and the leaked photos and documents [ 3 ]
- Tokyo Shimbun runs a wire item headlined that photos and documents leaked through unauthorized access [ 4 ]
- Nishi-Nippon Shimbun runs the same wire headline [ 5 ]