Notice of unauthorized access to customer information
Published: 31 July 2026
Og Co., Ltd.
We are writing to inform you that our system was subject to unauthorized access by a third party, and that some information belonging to customers using our Travel Plan may have been leaked.
We sincerely apologize for any concern this may cause to our customers and to everyone affected.
■ Who is affected
AFFECTED
Customers on our Travel Plan who fall into either of the following categories 44,399 customers in total.
- Customers who placed an order on or after 4 November 2025 and on or before 27 July 2026
- Customers who placed an order on or before 3 November 2025 with a service start date on or after 4 November 2025
The Travel Plan is our short-term plan, for which you specify your usage period when placing your order. It covers SIM cards, eSIMs, and Pocket WiFi alike.
Affected customers are being contacted individually by email at their registered address on 31 July 2026. If you are unsure whether you are affected, please contact us using the details below.
NOT AFFECTED
- Customers on our Monthly Plan (SIM cards, eSIMs, and Pocket WiFi alike)
- Home WiFi customers
- Sakura Fiber Internet customers
Customer information relating to these services was not involved in this incident.
- *SIM cards, eSIMs, and Pocket WiFi are all offered under both our Travel Plan and our Monthly Plan. Whether you are affected depends on the plan you signed up for, not on the type of product.
■ Information that may have been viewed
- Your name
- Your email address
- Your order details (product purchased, order date, amount charged, and how you received your order)
- Your payment method type
- The delivery address provided when placing your order (if your order was delivered to your accommodation or to a location of your choice)
■ Information NOT affected by this incident
- Payment details, including credit card numbers
- Password information
We do not store credit card numbers on our company's systems; they are stored by our payment provider.
Our payment provider was unaffected by this incident, and information retained by them remains secured.
Therefore, there is not a high risk that fraudulent card use or impersonation will occur as a result of this incident.
■ Information NOT retained by us
- Phone number (our order form has no field for it)
- Identity documentation (e.g. passport, residence card)
- Date of birth
■ What happened and what we have done
- 27 July 2026Unauthorized access to our system from outside the company was detected
- Same dayWe closed the route of entry and replaced credentials
- 30 July 2026We reported the incident to the relevant Japanese authorities
- 31 July 2026We are contacting affected customers individually by email
We are implementing measures to prevent recurrence.
■ Please be aware of communications pretending to be from us
There is a chance that a third party may pretend to be Sakura Mobile and contact you, mentioning your name and email address. Please be aware of the following points:
- All communications from us are sent from an @sakuramobile.jp domain
- We will never request your payment details or personal information by email
- Double check any links or attachments sent to you before opening them
- To visit our website, please use a search engine or a saved bookmark
■ Measures to prevent recurrence
- Enforcing two-factor authentication for access to our management systems
- Establishing formal procedures for password management and regular password changes
- Strengthening our ability to detect and block unauthorized access
- Reinforcing monitoring and reviewing our internal response procedures
■ Contact
privacy@sakuramobile.jp
Hours: 10:00-17:00 (Japan Standard Time)
We apologize again for any concern caused.
Og Co., Ltd.
Sakura Mobile
Tomoki Sunaga, Representative Director
Revision history
31 July 2026 First published