Download Privacy Needle App

Type to search

Data Breaches

Japan’s Digital Agency Data Breach Affects 240,000 People

Share

Japan’s Digital Agency has disclosed a data breach affecting the personal information of approximately 240,000 individuals.

The incident involved the agency’s Government Solution Service (GSS). An investigation conducted in July determined that attackers exploited a vulnerability in a VPN product to gain unauthorised access to the system.

The agency reported that more than 246,000 records were compromised. The stolen data includes approximately 236,000 names, 231,000 email addresses, 94,000 phone numbers, and roughly 1,000 addresses.

The compromised information belongs to users, public officials, administrative staff, and various businesses or individuals working with the GSS. The agency clarified that most of the exposed addresses and phone numbers are linked to professional locations, such as government buildings or offices, rather than private residential data.

Scope of the Compromise

The agency confirmed that sensitive identifiers, including individual identification numbers and financial account information, were not affected by the breach. Additionally, no other agency systems were compromised, and no information belonging to the general public was accessed.

The breach was first detected in late June after hackers utilised a maintenance and operations employee’s account to access files. In response, the agency blocked external access to the affected server and suspended the compromised account immediately upon confirming the exploitation.

While the specific VPN product was not named, the agency noted that the vulnerability in question had been publicly disclosed prior to the confirmation of the attack. The agency has stated it will strengthen its vulnerability management protocols to prevent further incidents.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.