“Unauthorized access at Rakuten Drive.”
This news came out today.
“Does this affect me?” That’s the natural reaction. It is.
First, a disclosure: the operator of this site is an employee of Rakuten Group, and also uses Rakuten Mobile referral links.
That is exactly why this article covers only facts confirmed in the reports. Anything that is speculation is written so you can tell it is speculation.
Summary in 30 seconds
- Rakuten Drive announced on October 6, 2026 that unauthorized access had occurred
- Stored data was obtained or viewed for 15,382 accounts
- Information such as account names was affected for 687 accounts. For 313 of those, encrypted passwords were also affected
- The cause is said to be that credentials for an administrator account of the system were obtained illegally
- Affected users are said to be notified individually
- It says that no secondary damage has been confirmed at this time
What is Rakuten Drive?
Rakuten Drive is a cloud storage service provided by Rakuten Group. It lets you keep data such as photos and documents stored on the internet.
The ASCII.jp report does not describe its features or pricing.
What happened (contents of the report)
This is what ASCII.jp reported as Rakuten Drive’s announcement.
What was affected
| Information | Count | Period / date |
|---|---|---|
| Stored data (photos, documents, etc.) | 15,382 accounts | Obtained or viewed from January 29 to September 17, 2026 |
| Account name, display name, profile image URL | 687 accounts | Obtained or viewed on August 27 |
| Encrypted password and the string added during encryption (salt) | 313 of the 687 above | Same as above |
Regarding passwords, Rakuten Drive is reported to have explained that processing was applied to make them difficult to restore.
Cause
It is said that credentials for an administrator account of the system were obtained illegally, and the system was accessed internally. How the credentials were leaked and the method used are not stated.
Rakuten’s response
The reported measures are as follows.
- The route of the unauthorized access was blocked, and monitoring was strengthened
- App downloads and the issuing of new accounts are restricted
- Affected users will be notified individually
- No secondary damage has been confirmed at this time
What is not stated yet
The body of the report does not state the following.
- When the unauthorized access was discovered
- How the credentials were leaked, or details of the method
- Specific measures to prevent recurrence, other than strengthened monitoring
- Specific guidance for users on actions such as changing passwords or enabling two-step verification
For details, check “【重要】「楽天ドライブ」における不正アクセスの発生について” (Important: Occurrence of Unauthorized Access on “Rakuten Drive”), posted on the Rakuten Drive support site (https://support.rakuten-drive.com/hc/ja).
I have not been able to check this official page itself. The content of this article is based on the ASCII.jp report.
What users should check
From here on, this is not official guidance. It is my own general advice.
1. Check whether you used Rakuten Drive
Look through the app list on your phone, and try to recall the data you saved. If you don’t remember using it, you are probably not affected, but confirm with the official notice to be sure.
2. Beware of impersonation posing as individual notifications
Affected users are said to be notified individually. At times like this, emails and SMS messages pretending to be official tend to increase.
- Do not enter your ID or password from a link in an email or SMS
- Check through the official app, or an official site you opened yourself
3. Review password reuse
If you used the same password as Rakuten Drive for other services, it is safer to change it. For services that support two-step verification, I recommend turning it on.
4. Take stock of what you had saved
Try to recall whether you stored important documents or personal information. It will help you decide what to do when a notification arrives later.
About other information seen on social media
On the same day, a claim about a different data leak is also being discussed on social media.
However, as far as I have checked, neither the truth of that claim nor the source of the leak is known. Please do not confuse it with this Rakuten Drive incident. This article does not cover it.
Summary
- On October 6, 2026, Rakuten Drive announced unauthorized access
- Stored data was obtained or viewed for 15,382 accounts. Account information was affected for 687 accounts (313 of them also had encrypted passwords affected)
- The cause is said to be illegal acquisition of administrator account credentials. No secondary damage has been confirmed at this time, it says
- The time of discovery, details of the method, and specific guidance for users are not stated in the body of the report
- Check the official notice for details. Beware of impersonating emails and SMS messages
Information may be updated. Please be sure to check the official notice.
Source: ASCII.jp
This article contains affiliate advertising. If you apply for a product or service through links on this site, we may receive compensation from partner companies. Additionally, the operator is an employee of Rakuten Group and may receive compensation through an employee referral program. Article content and evaluations are based on the operator's actual experience and research, regardless of advertising. For details, see the Disclaimer & Affiliate Disclosure. Disclaimer & Affiliate Disclosure
This article contains machine translation. For official terms, please refer to the multilingual pages on the official Rakuten Mobile website.
If you have concerns about Rakuten Mobile's coverage area or signal conditions, you can inquire through the official signal improvement survey request form .