Japan’s Digital Agency Data Breach Affects 240,000 People
Share
Japan’s Digital Agency has disclosed a data breach affecting the personal information of approximately 240,000 individuals.
The incident involved the agency’s Government Solution Service (GSS). An investigation conducted in July determined that attackers exploited a vulnerability in a VPN product to gain unauthorised access to the system.
The agency reported that more than 246,000 records were compromised. The stolen data includes approximately 236,000 names, 231,000 email addresses, 94,000 phone numbers, and roughly 1,000 addresses.
The compromised information belongs to users, public officials, administrative staff, and various businesses or individuals working with the GSS. The agency clarified that most of the exposed addresses and phone numbers are linked to professional locations, such as government buildings or offices, rather than private residential data.
Scope of the Compromise
The agency confirmed that sensitive identifiers, including individual identification numbers and financial account information, were not affected by the breach. Additionally, no other agency systems were compromised, and no information belonging to the general public was accessed.
The breach was first detected in late June after hackers utilised a maintenance and operations employee’s account to access files. In response, the agency blocked external access to the affected server and suspended the compromised account immediately upon confirming the exploitation.
While the specific VPN product was not named, the agency noted that the vulnerability in question had been publicly disclosed prior to the confirmation of the attack. The agency has stated it will strengthen its vulnerability management protocols to prevent further incidents.




Leave a Reply