The Once Times

Asia

Rakuten Drive Hit by "Hacked" Push Notifications Demanding Payment

Rakuten Mobile Says It's Investigating Urgently, Warns Users Not to Tap or Pay

3 min read

TOKYO — Rakuten Mobile (楽天モバイル) is investigating a wave of suspicious push notifications sent through its cloud storage service Rakuten Drive (楽天ドライブ), after users across Japan reported receiving threatening pop-ups claiming their accounts were hacked and demanding payment.

Notifications from Rakuten Drive / X @UmeboshiGohan
Notifications from Rakuten Drive / X @UmeboshiGohan

The notifications began appearing on the morning of July 30, with messages including "YOUR RAKUTEN DRIVE HACKED," "ALL YOUR DATA ALL LEAKD," and "Your payment was declined," some accompanied by buttons labeled "PAY NOW" or "UPDATE PAYMENT." Screenshots circulating on social media show one notification warning users they had 24 hours to pay 2,000 dollars before their files would be deleted and removed, with several users pointing to spelling errors in the messages as an early sign they weren't genuine.

Rakuten Drive's support team acknowledged the issue on its official help site the same day, describing the notifications as unauthorized and appearing to originate from the app itself, though the company has not disclosed how they were sent or whether they are linked to any actual security breach. The company said a dedicated team was conducting an "emergency investigation" and promised updates as soon as new information became available.

Important Security Notice by Rakuten Drive / Rakuten Drive Support
Important Security Notice by Rakuten Drive / Rakuten Drive Support

In its advisory, Rakuten instructed users not to tap any links or buttons within the notifications or pop-ups, not to enter passwords, payment details, or other personal information, and not to make any payment requested through the messages. Users who had already opened a notification were told to stop interacting immediately and simply close the pop-up and the app.

As of publication, Rakuten has not confirmed whether user data was actually accessed or leaked, nor has it identified the cause of the unauthorized notifications. The ambiguity has left many users uncertain about the actual state of their accounts, with some reporting they were locked out of the app entirely while trying to investigate the alerts themselves.

What's Known So Far

  • The notifications appear to have been sent through Rakuten Drive's own official app, not via email or SMS, making them harder for users to dismiss outright.

  • Reported message variants include claims of account hacking, data leaks, payment failures, account suspension, and file deletion threats.

  • Rakuten has explicitly avoided confirming or denying an actual breach, framing its response purely around the notifications themselves rather than underlying account security.

The incident echoes a familiar pattern in mobile scams, where urgency and threat of loss are used to pressure users into fast, unverified payments, though what's unusual here is the apparent use of the legitimate app's own notification channel rather than an external phishing link. Rakuten's own broader anti-fraud pages already warn customers about email phishing schemes impersonating its brand, suggesting attackers may be adapting known tactics to a new delivery method. Whether this stems from a compromised notification pipeline, a third-party integration issue, or something else entirely remains the central question Rakuten has yet to answer publicly.

#Rakuten #Rakuten Drive #Rakuten Mobile #楽天ドライブ #楽天モバイル

You might like

Editor's Picks