- Rakuten Mobile reported an unauthorized access incident that occurred on Thursday, July 30, 2026, in its cloud storage service “Rakuten Drive,” through a direct message sent to affected users entitled “[Important Rakuten Drive] Apology and Notice Regarding Unauthorized Access to the Push Notification Delivery System (8/28/2026).”
- On Thursday, July 30, 2026, at around 12:55 PM, unauthorized access occurred to the push notification delivery system used by “Rakuten Drive,” which is provided by an external vendor.
- Investigations revealed that the registered email addresses of some “Rakuten Drive” users and unique system IDs used to identify users on the push notification delivery system may have been viewed by a third party.
On Friday, August 28, 2026, Rakuten Mobile reported an unauthorized access incident that occurred on Thursday, July 30, 2026, in its cloud storage service “Rakuten Drive,” via a direct message sent to affected users entitled “[Important Rakuten Drive] Apology and Notice Regarding Unauthorized Access to the Push Notification Delivery System (8/28/2026).”
According to Rakuten Mobile, unauthorized access occurred at around 12:55 PM on Thursday, July 30, 2026, targeting the push notification delivery system used by “Rakuten Drive” and provided by an external vendor. This unauthorized access was reportedly resolved at around 4:27 PM on the same day.
However, as a result of the investigation, it was found that the registered email addresses of some users and the unique system IDs used to identify users on the push notification delivery system may have been viewed by a third party. In other words, it appears that email addresses and unique system IDs may have been leaked.
It has also been confirmed that unauthorized app notifications were sent to some users as a result of this “Rakuten Drive” unauthorized access incident.

Meanwhile, passwords, data stored in “Rakuten Drive,” payment information such as credit cards, addresses, and phone numbers have not been leaked, and no unauthorized access to “Rakuten Drive” itself has been confirmed. Furthermore, the company stated that even if the unique system IDs of the push notification delivery system were leaked to a third party, it would not impact the users.
However, since email addresses may have been leaked, there is a risk that phishing emails or similar messages based on them could be sent in the future. That said, because email addresses are information that can leak from anywhere, improving IT literacy to spot and remain cautious against suspicious emails is ultimately the best defense.
As countermeasures against the unauthorized access to “Rakuten Drive,” Rakuten Mobile has stopped unauthorized app notifications, blocked unauthorized access to the push notification delivery system provided by the external vendor, strengthened security measures and monitoring systems, and reported the incident to the relevant authorities.
お客さま各位
平素より「楽天ドライブ」をご利用いただき、誠にありがとうございます。
本メールは、「楽天ドライブ」をご利用いただいているすべてのお客様にお送りしております。この度、社外の事業者が提供するプッシュ通知配信システムにて「楽天ドライブ」が使用するアカウントに対して、不正アクセスがあったことが判明いたしました。
お客様にご迷惑をお掛けしましたこと、心より深くお詫び申し上げます。つきましては、本件の概要および当社の対応についてご案内差し上げます。
■ 発生した事象
2026年7月30日(木)午後0時55分頃、社外の事業者が提供するプッシュ通知配信システムにて「楽天ドライブ」が使用するアカウントに対する不正アクセスを確認いたしました。
調査の結果、「楽天ドライブ」に登録されている一部のお客様のメールアドレスおよび、プッシュ通知配信システムにおいてお客様を識別するための固有IDが、不正アクセスを行った第三者に閲覧された可能性があることが判明しております。
また、不正アクセスを行った第三者により、一部のお客様に対して不正なアプリ通知が送信されたことも確認いたしました。不正なアプリ通知の詳細につきましては、「楽天モバイル」公式サイトの「お知らせ」ページにて公表しておりますので、以下をご確認ください。
https://network.mobile.rakuten.co.jp/information/news/other/3809/
なお、本事象については2026年7月30日(木)午後4時27分頃に解消しております。■ 不正アクセスを行った第三者に閲覧された可能性のある情報
・「楽天ドライブ」にご登録いただいたメールアドレス
・プッシュ通知配信システムにおいてお客様を識別するための固有ID
※お客様のパスワード、「楽天ドライブ」に保存されているデータ、クレジットカード等の支払い情報、住所、電話番号等の漏洩、「楽天ドライブ」のサービス自体への不正アクセスは確認されておりません。
※不正アクセスを行った第三者に「プッシュ通知配信システムにおいてお客様を識別するための固有ID」を知られた場合であっても、お客様への影響は生じません。■ 当社の対応
不正アクセス判明後、主に以下の対応を実施しております。
・不正なアプリケーション通知の停止
・社外事業者提供のプッシュ通知配信システムに対する不正アクセスの遮断
・セキュリティ対策および監視体制の強化
・お客様へのプッシュ通知に関する注意喚起
・関係当局への報告■ お客様へのお願い
メールアドレスが閲覧された可能性があるため、フィッシングメール(スパムまたは詐欺メール)等が送信される可能性がございます。不審なメールを受信した場合は、リンクのクリックや添付ファイルのダウンロード前に、送信元とリンク先のURLを必ずご確認いただきますようお願い申し上げます。
なお、「楽天ドライブ」がプッシュ通知またはメールにて、お客様にパスワードの提供をお願いすることはございません。公式のログインページ以外でパスワードの入力を求められた場合は、直ちに当該ページを閉じてください。この度は、ご迷惑をおかけしましたことを、重ねてお詫び申し上げます。
「楽天ドライブ」では、今回の事態を厳粛に受け止め、全社を挙げてセキュリティ対策の強化に取り組み、再発防止に努めてまいります。
楽天ドライブからの不審な通知に関するお問い合わせ窓口
・楽天ドライブお問い合わせフォーム
https://support.rakuten-drive.com/hc/ja/requests/new・不審なプッシュ通知に関しての臨時サポート窓口
【重要 楽天ドライブ】プッシュ通知配信システムへの不正アクセスに関するお詫びとお知らせ(2026/8/28)
電話:0800-600-6600(年中無休 9:00-17:00/日本語対応のみ)
Source:Rakuten Mobile





