Skip to content
>_ITDITDWeb Security Platform

Security Guides

Rakuten Drive breach (stored data of 15,382 accounts): what was accessed and what users should do

Unauthorized access to part of Rakuten Drive's systems led to the stored data (photos, documents) of 15,382 accounts being obtained and viewed. What was affected and what users should do today.

Published 2026-10-06 Updated 2026-10-06 Last verified 2026-10-06 12 min read

For: people who use (or used) Rakuten Drive, and anyone who runs a service that stores users' files. This article is based on Rakuten Drive's official notice and does not cover attack techniques.

What users should do today

1

Check whether you received an individual notice

The service says it will notify affected users individually by email or other means. Check the inbox and spam folder of the email address registered with Rakuten Drive.

Fake emails imitating the notice may also appear. Do not sign in from a link in an email; open the service yourself from a bookmark or the app. For questions, use Rakuten Drive's inquiry form or its temporary support line (0800-600-6600 in Japan, every day 9:00–17:00 Japan time, Japanese only).

2

Review what you stored, and act as if it has been seen

If you used Rakuten Drive to back up photos or keep documents, list what you stored. If you are told you are affected, assume a third party has seen those contents.

  • Driver's license images: follow what to do if your driver's license data leaks so you notice accounts opened in your name early
  • Images of a national ID card, passport or health insurance card: likewise, watch for contracts or bills you do not recognize
  • Contracts, invoices or documents showing bank details: verify any contact from businesses or banks using contact details you look up on their official site, not those printed on the document
  • Photos of other people or documents containing others' personal data: if it is work data, report it to the responsible department at your workplace
3

Change your password, and any other service where you reused it

For 313 accounts, the encrypted password and the string added during encryption were obtained and viewed. This processing is meant to make the original password hard to recover, but short or guessable passwords can sometimes be guessed given enough time (how this works: how to store passwords safely).

If you sign in with an email address and password, reset it from "Forgot your password?" in Rakuten Drive. According to the service's help pages, a new password must be at least 8 characters and include at least one uppercase letter, lowercase letter, number and symbol. If you use the same password on other services, change it there too (to check for leaks: how to check if your password was leaked; to manage them: password managers).

4

If you sign in with Rakuten ID, Google or Apple, check that account's settings

According to the service's help pages, if you sign in with Rakuten ID, Google, Facebook or Apple, Rakuten Drive does not store those passwords. The passwords obtained and viewed in this incident were ones stored by Rakuten Drive.

Even so, that account is the door to your files. Turn on two-step verification on the account you use to sign in (the idea: getting started with multi-factor authentication). In Rakuten Drive's security settings, you can review the list of signed-in devices and sign out any you do not recognize.

5

Do not respond to messages, payment demands or threats claiming to be Rakuten Drive

The service asks users who notice unexpected payment demands, threatening messages or apparent impersonation not to open or respond, and to consult Rakuten Drive's support or the police.

If someone demands payment with threats such as "we will publish your photos" or "we will delete your files", do not pay and do not reply. In Japan, you can also call the police consultation line (#9110). How to recognize fake notices and emails: what is phishing.

Going forward: do not keep ID document images in cloud storage unless you need to

Cloud storage is useful because photos and documents survive even if your device breaks. On the other hand, when the service's own systems are accessed without authorization, as in this case, the contents can be seen regardless of how well you manage your password.

A practical split is to delete images of a driver's license or national ID card once you have submitted them, and keep anything you must retain in an encrypted area on your device or on paper. A different way files leak, through public sharing settings, is covered in cloud storage public exposure.

What happened (from Rakuten Drive's notice)

Rakuten Drive published its notice on October 6, 2026. Everything below is based on that notice.

  1. January 29 – September 17, 2026

    The period during which data stored on Rakuten Drive (including photos and documents) was obtained and viewed (event 3).
  2. August 27, 2026

    The date on which account names and other information were obtained and viewed (events 1 and 2).
  3. October 6, 2026

    Notice published. The service said it is notifying affected users individually by email or other means and has reported to the relevant authorities.
15,382
Accounts whose stored data (photos, documents) was obtained and viewed
313
Accounts whose encrypted password and related data were obtained and viewed
687
Accounts whose account name, display name and profile image URL were obtained and viewed
None confirmed
Secondary damage caused by the incident (as of October 6)
Information obtained and viewed (from Rakuten Drive's notice)
How
A third party illegitimately obtained the credentials of a management account for part of the systems Rakuten Drive uses, and accessed the systems
Event 1 (August 27)
687 accounts: account name, display name (the nickname shown to others when sharing files), profile image URL
Event 2 (August 27)
313 accounts: account name, display name, encrypted password, the string added during password encryption, profile image URL
Event 3 (January 29 – September 17)
15,382 accounts: data stored on Rakuten Drive (including photos and documents)
Secondary damage
No secondary damage caused by the incident has been confirmed so far
Response
Cut off the access route and strengthened monitoring, restricted app downloads and new account creation, posted a notice and notified affected users by email or other means, reported to the relevant authorities
Contact
Rakuten Drive inquiry form / temporary support line 0800-600-6600 (every day 9:00–17:00 Japan time, Japanese only)

How this differs from earlier notices

On July 30, 2026, suspicious push notifications that appeared to come from the Rakuten Drive app were shown, with English subject lines such as "YOUR RAKUTEN DRIVE HACKED" and "Your payment was declined". The service asked users not to open them, temporarily suspended its website to check its safety, and resumed it on August 4.

In its August 13 update on that event, the service said that unauthorized third-party access to data stored on Rakuten Drive had "not been confirmed at present". The October 6 notice says it has confirmed that stored data was obtained and viewed between January 29 and September 17.

On the relationship between the two notices

The October 6 notice does not mention any relationship to the July push-notification event. This site has no basis to judge whether the two share a cause, so we do not speculate.

What matters for users: even if you understood in August that your stored data was fine, you need to check again based on the October 6 notice whether you are affected.

What the obtained information could be used for

What sets this case apart is that the files users stored were themselves affected, not only contact or account details. What you should do depends on what you stored.

Stored files (ID documents, contracts, photos)

↓

Misuse of your identity; scams or threats using the contents

→ List what you stored / prepare for ID misuse / do not respond to threats

Encrypted password + added string

↓

Weak passwords may be guessed over time

→ Change it / change it wherever you reused it

Account name and display name

↓

Fake messages claiming to be Rakuten Drive, addressed correctly

→ Do not sign in from links

The affected information and the matching action for users

Fixed by changing them

  • Your password (can be reset)
  • Passwords you reused on other services
  • Display name and profile image

Cannot be taken back

  • The contents of the files you stored
  • Name, address, date of birth and numbers on ID documents
  • The people and places in your photos

Reading the notice: "no secondary damage confirmed" does not mean "safe from now on"

The service says that no secondary damage caused by the incident has been confirmed so far. That means none has been found yet; it does not mean the obtained information will never be used.

The details on ID documents do not change over time. Because misuse can happen months or years later, stay alert for a while to contracts or bills you do not recognize.

For people who run services that store users' files

According to the notice, a third party illegitimately obtained the credentials of a management account for part of the systems. How the credentials were obtained has not been disclosed, so this section sticks to points any service that stores users' files can review.

1

List which user data each management account can read

Check whether management accounts used for maintenance and operations actually need to read users' stored files. Remove read permissions that are not needed for the job, and as a baseline put opening users' files behind a separate permission (the idea: authentication vs. authorization).

2

Require multi-factor authentication and source restrictions for management accounts

Make sure that even if the password or key of a management account falls into someone else's hands, that alone is not enough to sign in. Combine multi-factor authentication (ideally a phishing-resistant method such as passkeys) with restrictions on where connections can come from.

3

Log and alert on management accounts reading user files

In normal operations, management accounts rarely read users' files. A good first step is to log every read of a user file by a management account and alert the responsible person whenever even a few occur in a day. Most cloud storage services offer read logging (access logs) and alerts based on them.

Sources (public record)

The facts in this article are based on the public information below. We do not speculate on intrusion methods or causes that have not been disclosed.

  • Rakuten Drive, "[Important] Unauthorized access to Rakuten Drive" (Japanese, October 6, 2026) — support.rakuten-drive.com
  • Rakuten Drive, "(Updated) [Important] Do not open suspicious notifications from Rakuten Drive" (Japanese, updated August 13, 2026) — support.rakuten-drive.com
  • Rakuten Mobile, "(Updated) [Important] Do not open suspicious notifications from Rakuten Drive" (Japanese, published July 31, updated August 13, 2026) — network.mobile.rakuten.co.jp
  • Rakuten Drive help pages, "Resetting your password" and "Checking and managing devices" (Japanese) — support.rakuten-drive.com

Update history

2026-10-06: First version, based on Rakuten Drive's notice of October 6. How the credentials were obtained has not been disclosed; this article will be updated when it is.

FAQ

QWhat was obtained and viewed in the Rakuten Drive breach?
A

According to Rakuten Drive's notice of October 6, 2026, three events were confirmed. (1) On August 27, 2026, the account name, display name and profile image URL of 687 accounts. (2) On the same day, the account name, display name, encrypted password, the string added during password encryption and profile image URL of 313 accounts. (3) Between January 29 and September 17, 2026, the data stored on Rakuten Drive (including photos and documents) of 15,382 accounts.

QAm I affected?
A

The service says it will notify affected users individually by email or other means. Check the inbox (including the spam folder) of the email address registered with Rakuten Drive. Do not sign in from a link in that email, though; open Rakuten Drive yourself from a bookmark or the app.

QWhat should I do if my stored files were affected?
A

List what you had stored and act as if it has been seen. If there were images of ID documents such as a driver's license or national ID card, set yourself up to notice misuse quickly (this site covers the steps for a driver's license in a separate article). If there were contracts, invoices or documents showing bank details, be careful with unexpected contact claiming to be the businesses or banks involved.

QShould I change my password?
A

For 313 accounts, the encrypted password and the string added during encryption were obtained and viewed. If you sign in to Rakuten Drive with an email address and password, changing your password is recommended. If you use the same password on other services, change it there too. If you sign in with Rakuten ID, Google, Facebook or Apple, Rakuten Drive says it does not store those passwords.

QWhat kind of contact should I watch for?
A

The service asks users who notice unfamiliar sign-ins, account anomalies, unexpected payment demands, threatening messages or apparent impersonation not to open or respond, and to consult Rakuten Drive's support or the police. Contacts are Rakuten Drive's inquiry form and its temporary support line (0800-600-6600 in Japan, every day 9:00–17:00 Japan time, Japanese only).

QIs this related to the suspicious push notifications in July?
A

On July 30, 2026, suspicious push notifications that appeared to come from the Rakuten Drive app were shown, and in its August 13 update the service said unauthorized third-party access to stored data had not been confirmed at that time. The October 6 notice says stored data was obtained and viewed between January 29 and September 17, 2026. The October 6 notice does not mention any relationship to the July event.