Japan Digital Agency VPN Flaw Exposes 246,000 Personnel Records
Share
Japan’s Digital Agency has confirmed a data breach that may have exposed approximately 246,000 records containing the personal information of government employees and public officials.
The agency revealed that attackers gained initial access by exploiting a vulnerability in a virtual private network (VPN) device used by the Government Solution Service (GSS).
The intrusion was detected following an investigation that began on 25 June, after the agency identified large-scale file access originating from the account of a maintenance and operations staff member. On 9 July, officials discovered that a third party had utilised a vulnerability in a network-connected device to gain unauthorised access to the system.
According to the agency, the potentially exposed data includes:
- 236,000 names
- 231,000 email addresses
- 94,000 telephone numbers
- 1,000 physical addresses
The breach affects government employees, public officials, and associated business entities and individuals who utilise the GSS system. However, the Digital Agency stated that the personal data of the general public was not compromised. Furthermore, sensitive information including “My Number” identification numbers, bank account details, and pension numbers was not included in the exposure.
While the specific VPN product and the exact vulnerability have not been named, the agency clarified that the flaw had a medium severity rating and was not a zero-day vulnerability.
Upon discovery, the agency suspended the compromised maintenance account and disconnected the affected equipment from external networks to prevent further unauthorised access. The incident was reported to Japan’s Personal Information Protection Commission on 15 July.
The agency has warned that individuals may face an elevated risk of phishing and impersonation attempts. Affected individuals will be contacted directly, and a dedicated support line has been established to assist those impacted.




Leave a Reply