Rakuten Drive Breach: Attackers Read 15,382 Users' Files for Nearly Eight Months

Rakuten Drive confirmed on 6 October 2026 that an administrator account was used without authorization and that files stored for 15,382 accounts had been accessible to an outside party for 231 days, after the company had said in August it found no evidence of such access.

Oct 06, 2026 - 20:23
0 10
Rakuten Drive Breach: Attackers Read 15,382 Users' Files for Nearly Eight Months

Rakuten Drive confirmed on 6 October 2026 that the login credentials of an administrator account for one of its systems were used without authorization, and that files belonging to 15,382 accounts had been accessible to an outside party for 231 days. The disclosure came less than eight weeks after the company's own help-centre notice stated there was no evidence of third-party access to data stored on the service.


Rakuten Drive Breach: Attackers Read 15,382 Users' Files for Nearly Eight Months

Tokyo, Japan — Rakuten Drive, the Rakuten group's cloud storage service, said on 6 October 2026 that a third party obtained the login credentials of an administrator account for one of its systems and used them to reach data stored on the service, affecting 15,382 accounts. The company said that access ran from 29 January 2026 to 17 September 2026, a span of 231 days. The notice was issued by Rakuten Symphony, the group company that operates Rakuten Drive, which Rakuten Mobile offers to its customers as an option service. It marks a reversal of the position the company had published in August, when its help-centre notice said there was no evidence of unauthorized third-party access to data stored on Rakuten Drive.

What Rakuten Confirmed on Tuesday

The 6 October notice confirms unauthorized access to "some of the systems" used by Rakuten Drive. Rakuten Symphony attributes the entry to a third party that illicitly obtained the login credentials of an administrator account and used them to reach the system. The company describes three sets of data as obtained or viewed, and states that no secondary harm attributable to the incident had been confirmed as of the notice date. Its stated response includes blocking the unauthorized access route, strengthening monitoring, restricting application downloads and new account issuance, publishing the notice, notifying affected customers individually by email and other means, and reporting the incident to the relevant authorities. Rakuten Drive has not said how the administrator credentials were stolen, which system they belonged to, how the access was discovered, why it took until September to stop it, what kinds of files were viewed, whether any were published or used for extortion, how many of the 15,382 accounts belong to businesses, or when app downloads and new sign-ups will resume.

231 Days Inside the File Store

The longest-running element of the incident is the access to stored data. Rakuten Drive says data held on the service itself, including photos and documents, was reachable for 15,382 accounts between 29 January 2026 and 17 September 2026. That is 231 days, more than seven months. The window is the only one of the three the company has described in terms of a start and end date; the other two are tied to a single day. It also runs well past the point at which the company had told users its service was safe. Rakuten Drive has not explained why the access continued for as long as it did or what ended it on 17 September. The company has not said what kinds of files were viewed, whether any were copied, or whether any were published or used to demand payment.

The August Sentence That Did Not Hold

Rakuten Drive's help-centre notice, last updated 13 August 2026, carried the line: "Currently, there is no evidence of unauthorized access by third parties to data stored on Rakuten Drive." By that date, according to the timeline the company published on 6 October, access to stored files had already been running for 196 days, nearly six and a half months. It continued for 35 days after the service's website reopened on 4 August 2026, following a suspension for a safety check, and ended only on 17 September 2026. The 6 October notice does not address the August statement directly. It also does not mention the July push-notification incident at all, and does not say whether the two episodes are connected.

A screenshot of Rakuten Drive's official notice of 6 October 2026 confirming unauthorized access to its systems. The notice states that data stored on Rakuten Drive for 15,382 accounts was obtained or viewed between 29 January and 17 September 2026. Photo: Rakuten Drive Support notice

What Was Taken, and What Was Not

Rakuten Drive separates the incident into three data events. The first covers account name, display name, meaning the nickname shown to the other party when a file is shared, and profile image URL, for 687 accounts, accessed on 27 August 2026. The second covers the same three items plus a password converted into a special string to make restoration difficult, and the string added during that encryption to make restoration difficult, for 313 accounts on the same date; the 313 is a subset of the 687. The third covers data stored on Rakuten Drive itself, including photos and documents, for 15,382 accounts, accessed between 29 January and 17 September 2026. The notice does not list credit-card numbers among the data involved in any of the three events. The company has not said how many of the affected accounts belong to businesses, nor what proportion of stored files were viewed.

One Administrator Account, Fifteen Thousand Users

The entry point described by Rakuten Symphony is a single administrator account, not a sweep of individual user logins. That distinction shapes what the company has and has not said. Rakuten Drive has not reported that user accounts were taken over one by one, and its guidance to customers is framed around spotting anomalies rather than around a forced credential reset for the 15,382. The company has not disclosed how the administrator credentials were obtained, which system the account belonged to, or how the intrusion was detected. It has also not given a total number of Rakuten Drive users, so the 15,382 cannot be expressed as a proportion of the customer base. Nor is Rakuten Drive a peripheral product: it launched as Sendy in 2019, joined the Rakuten group when Rakuten Mobile acquired the South Korean file-transfer company Estmob in 2021, was renamed Rakuten Symphony Korea in 2022, and had its full-scale commercial launch in Japan on 6 February 2024.

The July Notifications That Said You Had Been Hacked

On 30 July 2026, around 12:55, suspicious push notifications appeared in the Rakuten Drive app, apparently sent from it, carrying English subject lines such as "YOUR RAKUTEN DRIVE HACKED" and "Your payment was declined." Other examples quoted by the company included payment failures, account suspensions, file deletions, account hacking and payment demands. The notifications led to a fake Google login page designed to steal a Google account, or to a screen demanding payment in Bitcoin. Rakuten Mobile said the incident was resolved at about 16:27 the same day. On 28 August 2026 the company reported that unauthorized access had occurred on 30 July to the push notification delivery system used by Rakuten Drive, which is provided by an outside vendor, and that registered email addresses of some users and unique system IDs may have been viewed. It said passwords, stored data, payment information, addresses and telephone numbers had not leaked.

A screenshot of the fake push notification that reached Rakuten Drive users on 30 July 2026, reading "YOUR RAKUTEN DRIVE HACKED" and "ALL YOUR DATA ALL LEAKED". Rakuten Mobile warned users not to open it; it led to a fake Google login page or a demand for payment in Bitcoin. Source: Wikimedia Commons (public domain)

Rakuten Denies the 101 Million Claim

Two days before the Rakuten Drive notice, on 4 October 2026, a post titled "SELLING Rakuten Japan 101M" appeared on a cybercrime forum, offering what the seller called a "rakuten.co.jp database" of about 101 million records for US$700. The sample records reportedly contain names, email addresses, telephone numbers, addresses, dates of birth, member ranks, Rakuten Point balances, account creation and last-login times, and flags for Rakuten Card, Rakuten Mobile, Rakuten Point Card, the PointClub app and newsletter opt-ins. No passwords and no credit-card numbers appear in the published sample. Rakuten Group told reporters: "We have not confirmed any fact that information leakage such as you have enquired about has occurred." Asked about 18 sample records, it said: "Upon checking within our company, we have not confirmed any such accounts." The claim remains unverified.

Reading a Forum Post Like a Reporter

Security Measures Lab examined 18 sample records against Rakuten PointClub's publicly published rank conditions and found no clear contradiction for the Regular, Silver and Gold records. It also stated that the rank conditions are public information and that a seller could generate consistent dummy data from them, so a match is not proof the data is real. Rakuten's own published domestic membership figure is "over 100 million," counting members who completed registration, logged in at least once and have not withdrawn. The sample reportedly includes records marked as withdrawn, so the 101 million figure cannot be directly equated with that membership number. The seller has posted similar unverified claims before, including 150 million Notion user records in August 2026 and 850 million China Mobile records in September 2026; neither company confirmed those claims. Rakuten has not confirmed any link between the forum post and the Rakuten Drive breach.

Two Disclosures This Year, and the 2020 Precedent

The 6 October notice is the second Rakuten-related security disclosure this year, following Rakuten Books Network, a Rakuten Books group company, which announced unauthorized access to one of its PCs on 21 August 2026. That PC was detected as compromised on 5 April 2026 and held the delivery information, meaning name, postcode, address and telephone number, of 33,333 customers from Rakuten Books order data of 18-19 May 2022 and 19-21 December 2023, along with information on business contacts and employees. Four and a half months passed between detection and disclosure, and the company said no leak of the information had been confirmed. The larger precedent is older. On 25 December 2020, Rakuten announced that a cloud-based sales management system had been reachable by an outside party, exposing records held by Rakuten Ichiba, Rakuten Edy and Rakuten Card. For the marketplace alone, access was possible from 15 January 2016 to 24 November 2020, four years and ten months, with a maximum of 1,381,735 records at risk, of which actual access was confirmed for 208.

What Users Should Do, and What Rakuten Still Owes

Rakuten Drive's guidance is to watch for a login you do not recognise or an account anomaly, an unexplained charge, a threatening communication, or contact you believe is impersonation. If any of those appear, the company says, do not open it or respond, and consult the Rakuten Drive desk or the police. Support runs through the Rakuten Drive enquiry form at support.rakuten-drive.com and a temporary telephone line, 0800-600-6600, open year-round from 09:00 to 17:00, in Japanese only. The company also stopped app downloads from the App Store and Google Play on 21 September 2026, described at the time as "system maintenance," and has not said when downloads and new sign-ups will resume. What remains unanswered is narrower than it looks: who used the credentials, how they were obtained, why the access ran for 231 days before it was ended, and what was in the files. Until Rakuten Drive answers those, its customers are being asked to take the company's word on the rest.

By Jessica Ali, Staff Writer

This article was produced with AI-assisted research and editorial support. Sources: Rakuten Drive support notice (6 October 2026); Rakuten Mobile notice (31 July, updated 13 August 2026); Rakuten Group disclosure on the cloud sales management system (25 December 2020); Rakuten Books Network notice (21 August 2026); ITmedia NEWS; ITmedia Mobile; Impress' Keta Watch; ASCII.jp; 週刊アスキー; Jetstream; すまほん; Security Measures Lab; Japan Cyber Watch; Yahoo! News Japan / ABEMA Times.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Jessica Ali

Editor-in-Chief at Global1.News. Atlanta-based journalist who cuts through the BS and tells it like it is. Lead anchor, host, and the voice you hear when the spin stops and the truth starts.

Comments (0)

User