Key takeaways

  • Rakuten Drive (楽天ドライブ), the Rakuten group's cloud storage service, said on October 6, 2026 that attackers had stolen the credentials of an administrator account for one of its systems.
  • Using that access, they viewed and took files stored by 15,382 users, including photos and documents, from January 29 to September 17, 2026: almost eight months.
  • On August 27, they also took account details for 687 users, and hashed passwords for 313 more.
  • In August, after fake push notifications reached users through the official app, Rakuten Drive said it had not found any unauthorized access to stored data. It now says that access had been going on since January. It has not said whether the two are connected.

What happened#

According to Rakuten Drive's notice of October 6, a third party obtained the login credentials of an administrative account for "some of the systems used by Rakuten Drive", and used them to get in. Three sets of data were affected:

Data When Accounts
Event 1 Account name, display name, profile image URL Aug 27, 2026 687
Event 2 Account name, display name, profile image URL, hashed password and salt Aug 27, 2026 313
Event 3 Files stored on Rakuten Drive, including photos and documents Jan 29 to Sep 17, 2026 15,382

Rakuten Drive says it has blocked the access route, strengthened monitoring, restricted app downloads and new sign-ups, reported the incident to the authorities, and is contacting affected users individually by email. It says it has found no secondary harm so far.

The earlier warnings#

The October notice does not mention it, but Rakuten Drive users had already been warned about suspicious notifications in July. The company's own help center shows this sequence:

Date (2026) Event
Jan 29 Earliest unauthorized access to stored files, according to the October notice
Jul 30, about 12:55 Users receive suspicious push notifications that appear to come from the Rakuten Drive app, such as "YOUR RAKUTEN DRIVE HACKED" and "Your payment was declined". They lead to fake Google login pages or screens demanding bitcoin
Jul 31 – Aug 4 Website suspended for safety checks. Passwords of some Rakuten IDs force-reset
Aug 13 Updated notice: "no unauthorized access by a third party to data stored on Rakuten Drive has been confirmed at this time"
Aug 27 Account details and hashed passwords taken (Events 1 and 2)
Sep 17 Last unauthorized access to stored files
Sep 21 App downloads from the App Store and Google Play stopped, described as "system maintenance"
Oct 6 Notice of the breach

Rakuten Drive has not said how the fake notifications were sent, or whether they are connected to the stolen administrator credentials. We are not assuming they are. But the dates overlap: the fake notifications arrived in the middle of the period when attackers were reading users' files, and the account data was taken two weeks after the company said no access to stored data had been found.

What we don't know yet#

Rakuten Drive has not said:

  • How the administrator credentials were stolen, and which system they were for
  • Whether the July push notifications are connected to this breach
  • How it found the access, and why it took until September to stop it
  • What kinds of files were viewed, and whether any were published or used for extortion
  • How many of the 15,382 accounts belong to businesses, which use Rakuten Drive's business plans
  • When app downloads and new sign-ups will resume

Our analysis#

"Not confirmed" again#

On August 13, Rakuten Drive told users that no unauthorized access to their stored data had been confirmed. By then, according to its own October notice, attackers had been reading users' files for more than six months.

The August statement was probably accurate as a description of what the company knew. But users read it as reassurance, and it was wrong about what had happened. It is the same lesson as Moonstar, which said in March that no customer data had been found to be taken, and in October that it may have been. A line like "no unauthorized access has been confirmed" describes the investigation, not the data. This case shows how far apart the two can be.

Files, not just contact details#

Most breaches we cover involve names, addresses and phone numbers. This one involves what people stored: photos and documents, which can include ID scans, contracts, medical papers or private pictures. That makes it more serious per account than a much larger leak of contact details. Rakuten Drive asks users to report threatening contacts to the police, which suggests it is considering the risk of extortion. It has not said whether any has occurred.

One administrator account, eight months#

The way in was an administrator account, not a flaw in each user's login. That is why individual users could not have prevented it with a stronger password. An administrator account that can reach thousands of users' files is exactly the kind of credential that needs multi-factor authentication, narrow permissions and alerts on unusual use. Rakuten Drive has not said what protection it had. Nor has it explained why access that continued for almost eight months, including through a public security incident in July and August, was not stopped sooner.

A separate claim: "101 million Rakuten records"#

On October 4, a post on a cybercrime forum offered what the seller called a "rakuten.co.jp database" of 101 million records for sale, according to Japanese media. Rakuten Group told reporters it had not confirmed any leak, and the data's authenticity is unverified. The sample reportedly shows Rakuten membership data such as points balances, not files stored on Rakuten Drive. No link between the two has been shown.

What this means for readers#

  • Check your email for a notice from Rakuten Drive. Affected users are being contacted individually.
  • Think about what you stored on Rakuten Drive between January and September 2026. If it included ID documents, financial records or other sensitive files, assume they may have been seen, and take steps such as watching for misuse of your identity.
  • Change your Rakuten Drive password, and any other account where you used the same one. If you entered your Google password on a page reached from a Rakuten Drive notification in July, change it and review your Google account's security activity.
  • Do not respond to threats or payment demands that mention your files. Rakuten Drive asks users to report them to its support line (0800-600-6600, Japanese only) or the police.

Japanese terms at a glance#

Japanese Reading Meaning
楽天ドライブ Rakuten Doraibu Rakuten Drive, cloud storage service
管理用アカウントの認証情報 kanri-yō akaunto no ninshō jōhō Administrator account credentials
保存データ hozon dēta Stored data (files)
プッシュ通知 pusshu tsūchi Push notification
現在確認されておりません genzai kakunin sarete orimasen "Has not been confirmed at this time"
二次被害 niji higai Secondary harm (misuse of leaked data)

We will update this article if Rakuten Drive explains how the credentials were stolen or whether the July notifications were connected.