Rakuten Group's cloud storage service, Rakuten Drive, announced on October 6 that some of its systems had been subjected to unauthorized access by a third party. It stated that authentication information for a system administration account was illicitly obtained, allowing internal access.
The most significant impact is on data stored on Rakuten Drive. It was confirmed that between January 29, 2026, and September 17, 2026, saved data, including photos and documents, from 15,382 accounts were accessed and viewed.
On August 27, account names, display names, and profile image URLs were accessed and viewed from 687 accounts. Among these, for 313 accounts, encrypted passwords and strings added to make restoration difficult during encryption were also targeted. According to Rakuten Drive, passwords have undergone processing to make them difficult to restore.
The company has blocked the unauthorized access route, strengthened its monitoring system, and restricted app downloads and new account registrations. Affected users will be notified individually. As of now, no secondary damage has been confirmed.