Attackers accessed stored photos, documents, and account credentials through a compromised administrator account between January and September 2026, while a threat actor simultaneously claims to be selling over 101 million Rakuten membership records on a cybercrime forum for $700
Rakuten Drive, the cloud storage service run by Japanese e-commerce and technology group Rakuten Group, disclosed on October 6, 2026 that attackers used stolen administrator credentials to view and exfiltrate files belonging to 15,382 users. The intrusion ran from January 29 through September 17, 2026, nearly eight months, and exposed photographs, documents, and other personal files that users had stored on the platform. The disclosure came more than a month after Rakuten Drive told users that no unauthorized access to stored data had been confirmed, and two days after a separate threat actor posted what they claim is a database of 101 million Rakuten membership records for sale on a cybercrime forum.

One of these incidents is confirmed and the other is not, but together they have put Rakuten’s security under heavy scrutiny. What I keep coming back to is how a single compromised administrator credential could give someone access to thousands of users’ private files for most of a year without triggering detection or intervention.
What Rakuten Drive has confirmed
According to the official disclosure notice published October 6, 2026, an unauthorized third party obtained the login credentials for an administrative account tied to “some of the systems used by Rakuten Drive.” With that access, the attacker could view and download files stored by 15,382 user accounts, including photographs, documents, and other uploads.
The notice splits the compromised data into three groups, each affecting a different set of users at a different point in the attack:
- 687 accounts had their account names, display names, and profile image URLs accessed on August 27, 2026.
- 313 accounts lost the same fields plus hashed passwords and salt values on the same date.
- 15,382 accounts had their stored files, including photos and documents, viewed and exfiltrated from January 29 to September 17, 2026.
The file access is a long-running intrusion into user content. The August 27 account data theft suggests the attacker escalated access or moved to a different system component later in the campaign. Because hashed passwords and salts were taken for 313 users, anyone among them who reused a password elsewhere faces credential-stuffing risk beyond the Rakuten ecosystem.
The detection timeline
The sequence of detection, public statements, and final disclosure is the part of this story I find hardest to read charitably, and it comes from Rakuten Drive’s own help center documentation and public notices.
Unauthorized access to stored files began on January 29, 2026, according to the October disclosure, and for the next six months nobody appears to have noticed. Then on July 30, at about 12:55, Rakuten Drive users began receiving suspicious push notifications through the official app. Messages such as “YOUR RAKUTEN DRIVE HACKED” and “Your payment was declined” appeared on their devices and pointed them to fake Google login pages or screens demanding Bitcoin payments. They were delivered through what looked like the legitimate app infrastructure, so this was a visible, alarming security event.
Between July 31 and August 4, Rakuten suspended the Rakuten Drive website for what it called safety checks, and passwords for some Rakuten IDs were force-reset. On August 13, Rakuten Drive updated its notice to say that “no unauthorized access by a third party to data stored on Rakuten Drive has been confirmed at this time.” That may have accurately described where the investigation stood on that day. In hindsight it was badly misleading, because attackers had already been reading users’ files for more than six months.
On August 27, two weeks after that statement, attackers accessed account details for 687 users and hashed passwords for 313. The last confirmed unauthorized access to stored files was September 17. On September 21, Rakuten Drive pulled its mobile app from the Apple App Store and Google Play, calling it “system maintenance.” The formal breach disclosure did not arrive until October 6.
📬 Stay Ahead of Cyber Threats
Get the latest cybersecurity news, critical vulnerabilities, threat intelligence, tutorials, and exclusive giveaways delivered straight to your inbox. No spam. Unsubscribe anytime.
Subscribe to the Newsletter →Rakuten Drive has not said how the fake push notifications were delivered through its official app, or whether they were connected to the stolen administrator credentials. The dates overlap heavily, though. The phishing notifications went out in the middle of the period when attackers were actively reading files, and the account data theft happened two weeks after the company said it had found no unauthorized access.
How one admin account exposed thousands of users
A stolen administrator credential is one of the most damaging ways a cloud service can fail. A flaw in user authentication or application code might expose individual accounts. An admin credential gives what security professionals call “god-mode” access: the ability to view, modify, or exfiltrate data across the whole user base without hitting per-user security controls.
Cloud storage services like Rakuten Drive usually use a layered access model. End users authenticate individually and reach only their own files. Behind them, administrative systems handle storage allocation, user provisioning, content moderation, support, and infrastructure maintenance. Those accounts often have broad read access to user data, because support staff need to troubleshoot file issues, moderation teams need to review flagged content, and engineers need access for debugging and migrations.
So the question is what protected this particular account. NIST SP 800-63B, the CIS Controls, and ISO 27001 call for privileged accounts to use multi-factor authentication, just-in-time access, behavioral analytics, and least privilege. An administrator account that can reach thousands of users’ files should raise alerts as soon as access looks abnormal: bulk downloads, activity outside working hours, logins from unusual locations, or patterns that don’t match the administrator’s normal workflow.
Rakuten Drive has not said whether multi-factor authentication was enforced on the compromised account, what monitoring was active, or why eight months of access went unnoticed. It has also not said which internal system the account belonged to, so we don’t know whether this was a storage backend, a customer support tool, a content management interface, or something else.
The duration matters. Continuous monitoring and user and entity behavior analytics (UEBA) exist to catch exactly this kind of sustained, anomalous access. Access continued through a very public incident in July and August, with a website suspension and forced password resets, and that did not prompt anyone to look at administrative access patterns. That points to either a gap in monitoring coverage or a failure to connect the July phishing incident to a deeper compromise.
Why this breach is worse than a typical data leak
The industry has grown numb to breach notices involving names, email addresses, and phone numbers. Those details are private, but on their own they rarely enable direct financial fraud or blackmail.
Files stored in a cloud service are different. Users put in identity documents (passport scans, driver’s licenses, national ID cards), financial records (bank statements, tax documents, pay stubs), medical records, legal documents (contracts, agreements, court filings), private photographs, and business documents. A leaked email address can be used for phishing. A stolen passport scan can be used for identity theft, for opening fraudulent accounts, or for social engineering against financial institutions. Private photographs can be used for extortion, and business documents can reveal trade secrets or client relationships. Rakuten Drive’s own guidance to affected users includes reporting threatening contacts to the police, which suggests the company itself sees extortion as a real risk.
The breach also shows how the service handles encryption. An administrator account could view and download user files, which confirms that Rakuten Drive does not use end-to-end encryption for stored content. The platform can decrypt files, which it needs for features like preview, search, and support. It also means any compromise of administrative infrastructure can expose stored content in plaintext.
The 101 million record claim
On October 4, 2026, two days before the official breach notice, a threat actor posted on a cybercrime forum offering a “rakuten.co.jp database” of 101 million records for $700. The listing, titled “SELLING Rakuten Japan 101M,” included sample records with names, addresses, phone numbers, email addresses, dates of birth, membership ranks, Rakuten Point balances, last login timestamps, and various service-usage flags.
Rakuten Group told reporters it has not confirmed any leak matching this claim, and the data’s authenticity is unverified. Researchers who examined the 18 sample records in the post found them internally consistent with Rakuten’s published membership tier structure. The relationship between membership rank (Regular, Silver, Gold, Platinum, Diamond) and the point-earning thresholds over a six-month period matched Rakuten Point Club’s published criteria. Records marked “Gold,” for example, showed 700 or more points and seven or more qualifying transactions, but fell below the Platinum threshold of 2,000 points and 15 transactions.
The samples also contained account creation dates, some going back to 1998 (Rakuten was founded in 1997), last login timestamps from September and October 2026, and flags for Rakuten Card ownership, Rakuten Mobile subscriptions, Point Club application usage, and newsletter subscriptions. No passwords or credit card numbers appeared in the sample data.
No verified link has been established between this claim and the Rakuten Drive breach. The data types differ, since the Drive breach involves stored files and a small number of account credentials while the listing describes membership and loyalty program data, and the scale differs by orders of magnitude. Still, the two events landing so close together has created a compound reputation problem for Rakuten and raised the question of whether other parts of its infrastructure are exposed.
Analysts see several possibilities. The listing could be a genuine exfiltration from Rakuten’s core membership systems, a compilation of data from earlier breaches and third-party sources, a fabrication built from public information and Rakuten’s published service specifications, or a mix of real records and synthetic padding. A price of $700 for 101 million records is very low even by cybercrime market standards. Some analysts read that as seller desperation, others as a sign the data is less fresh or less exclusive than claimed.
“Not confirmed” is not “did not happen”
Rakuten Drive joins a growing list of organizations that gave reassuring public statements which fuller disclosures later contradicted. On August 13 the company said that no unauthorized access to stored data “has been confirmed at this time.” As a description of the investigation’s status that was defensible, but users read it as reassurance that their data was safe, and six months of file access had already happened.
The Japanese wording, 現在確認されておりません (genzai kakunin sarete orimasen), translates literally to “has not been confirmed at this time,” and readers hear “your data is safe.” What an ongoing investigation has found so far and what has actually been compromised can be very far apart.
Other 2026 breaches follow the same pattern. Moonstar, another Japanese company, said in March that it had found no customer data taken, then disclosed in October that data may have been exfiltrated. Legal and communications teams want to avoid confirming a breach too early, and that pull works against the obligation to tell users about potential risk in time.
For teams writing incident communications, the lesson is that no confirmed compromise is not evidence of security. Statements should say what the investigation has not yet covered and avoid language that implies finality. “Our investigation is ongoing and we will update users as new information becomes available” protects an organization’s credibility better than a definitive-sounding reassurance issued mid-investigation.
Rakuten’s wider security history
These incidents have company. In August 2026, Rakuten Books Network disclosed unauthorized access to certain company computers, first identified on April 5, 2026. The affected systems held delivery information for 33,333 Rakuten Books customers, including names, postal codes, addresses, and phone numbers tied to orders placed in May 2022 and December 2023. Rakuten Books Network said at the time that it had not identified any confirmed exfiltration.
In 2020, Rakuten Group disclosed that a misconfigured cloud-based sales management system had allowed unauthorized third-party access to data managed by Rakuten, Rakuten Card, and Rakuten Edy. Information on up to 1,381,735 prospective and contracted Rakuten Marketplace vendors was potentially accessible, with access confirmed for 208 records. Rakuten Card business loan applicant information and Rakuten Edy device balance transfer service applicant information were also affected.
Different subsidiaries, different data, different attack vectors, but together they point to the difficulty of securing a very large, multi-service ecosystem. Rakuten Group runs more than 70 services across e-commerce, fintech, telecommunications, travel, and digital content, all under a single Rakuten ID. With identity and activity data concentrated that way, a compromise in one component can spread.
What affected users should do
Rakuten Drive says it is contacting affected users individually by email and has reported the incident to the relevant authorities. It has blocked the access route the attackers used, strengthened monitoring, and restricted app downloads and new registrations. As of the disclosure date it reports no secondary harm, meaning no evidence the stolen data has been used in further attacks.
If you used Rakuten Drive between January and September 2026, security professionals recommend the following:
- Check your email for a direct notification from Rakuten Drive. It will say what data was accessed.
- List what you stored on Rakuten Drive during the affected period. If you uploaded identity documents, financial records, medical papers, legal contracts, or sensitive photographs, assume those files may have been viewed or copied. Monitor for identity theft, place fraud alerts with credit bureaus, or notify the relevant institutions.
- Change your Rakuten Drive password now, along with the password on any other account where you used the same one. With hashed passwords and salts stolen for 313 accounts, offline cracking is possible, especially if weak hashing algorithms were used or users chose common passwords.
- If you got the suspicious push notifications in July and clicked through to a fake Google login page or a Bitcoin payment screen, change your Google account password and review that account’s security activity log for unauthorized access.
- Do not respond to threats, blackmail demands, or payment requests that mention your stored files. Rakuten Drive asks users who receive them to report to its support line (0800-600-6600, Japanese only) or to local police.
If you are worried about the 101 million record claim, review your Rakuten ID login history for access you don’t recognize, check your order history for purchases you didn’t make, confirm your registered email and shipping addresses haven’t changed, and watch your Rakuten Point balance for unusual activity. Be skeptical of any message that cites your membership rank, point balance, or service usage, because those details could make a phishing attempt far more convincing.
End-to-end encryption
When a storage provider can decrypt user files, as Rakuten Drive evidently can, every compromise of its administrative infrastructure is a potential mass exposure, and the provider becomes a single point of failure for the confidentiality of every stored file.
Services such as Proton Drive, Tresorit, and certain configurations of Sync.com use end-to-end encryption, where encryption and decryption happen only on the user’s device. The server stores ciphertext and never holds the keys. With that design, a stolen administrator credential would yield encrypted blobs, and the attacker would still have to compromise individual user devices or passwords to read anything. File metadata such as names, sizes, and upload dates might be visible, but not the content.
There are costs. End-to-end encryption rules out server-side file search, content preview, AI-powered organization, and content moderation, and users who lose their passwords or recovery keys lose their files permanently. For people storing sensitive documents, the Rakuten Drive breach shows what the alternative costs: if the service can read your files, anyone who compromises the service can too.
Regulatory and industry implications
Japan’s Act on the Protection of Personal Information (APPI), amended in 2022 and still subject to regulatory guidance, requires businesses that handle personal data to notify affected parties of breaches. The Personal Information Protection Commission (PPC) oversees compliance and can issue recommendations and orders to organizations that fail to protect personal information.
The eight-month detection window is likely to draw regulatory attention. Under APPI guidelines, organizations are expected to apply security measures matched to the sensitivity of their data and to detect and respond to incidents in a timely way. An administrative credential compromise that lasted nearly eight months and spanned a public phishing incident may be read as a control failure rather than a simple technical oversight.
For cloud storage and SaaS providers more broadly, the incident points to several operational basics:
- Administrators should get access only to the data and functions their role requires, and only for as long as they need it.
- Privileged access should require phishing-resistant multi-factor authentication, such as hardware security keys or platform authenticators, and not SMS one-time codes.
- All administrative access should be logged immutably and watched by behavioral analytics that can flag anomalies in real time.
- Privileged sessions should be time-limited, with re-authentication for extended operations.
- Access reviews should regularly find and remove administrator accounts that are no longer needed.
Tabletop exercises and red team tests should also cover administrative infrastructure. Many organizations test their defenses against attacks on user-facing applications and pay less attention to internal admin systems, which often run older software, get patched less often, and use weaker authentication because they are assumed to be reachable only by trusted insiders.
What remains unknown
Several questions are still open after the October 6 disclosure:
- Rakuten Drive has not said how the administrator credentials were stolen: phishing, credential stuffing, malware on an administrator’s workstation, an insider, or a compromised third-party system.
- It has not named the system the administrator account was associated with, so the full scope of access is unclear.
- It has not said whether the July push notification phishing campaign was the same attacker or a separate incident.
- It has not explained why the access wasn’t detected and shut down sooner, particularly in July and August when security attention was high.
- It has not said what files were accessed beyond “photos and documents,” whether any have been published or used for extortion, or how many of the 15,382 accounts belong to business users on enterprise plans.
- It has given no timeline for when app downloads and new registrations will resume. The app has been off the App Store and Google Play since September 21, for more than two weeks now.
Rakuten Group still owes users an account of how the credentials were compromised, which systems were affected, and what is changing to prevent a repeat. The unresolved 101 million record claim makes that more pressing, since a confirmed file breach alongside an unverified mass-data sale will not be settled by corporate reassurance without concrete technical detail.
This article will be updated as Rakuten Drive provides more information about the breach, the status of the 101 million record claim, and the timeline for restoring service. If you have information relevant to this incident, contact the editorial team.









