ZeroHour
Security Affairspublished ()ingested Pierluigi Paganini1
Part of a story covered by 2 sources: “Patchable VPN flaw exposed ~246,000 records of Japanese government personnel across 23 ministries” — merged summary and timeline →

Non-Zero-Day VPN Flaw Left Japan ‘s Government Shared Network Platform Exposed: 246,000 Records at Risk

highData breachimportance 72
AI summary · glm-5.3

Japan's Digital Agency says attackers exploited a patchable VPN flaw to access a government shared platform, exposing records of ~246,000 employees across 23 ministries.

Japan's Digital Agency disclosed that attackers exploited a medium-severity, already-patchable vulnerability in a VPN device to access the Government Solution Service (GSS), potentially leaking personal data of roughly 246,000 government employees, officials, and contractors across 23 ministries. The intrusion was detected on June 25 and confirmed as VPN exploitation on July 9, with public disclosure 78 days after detection. Exposed data includes about 236,000 names, 231,000 email addresses, 94,000 phone numbers, and 1,000 physical addresses; no My Number, bank account, or pension numbers were included. The compromised maintenance staff account was suspended and the compromised hardware isolated, but the VPN product and flaw were not disclosed.

  • Patchable medium-severity VPN flaw enabled access to shared platform for 23 ministries.
  • Approximately 246,000 records of officials and contractors potentially leaked.
  • Public disclosure came 78 days after initial detection on June 25.
  • No My Number, bank, or pension numbers exposed; no confirmed misuse reported.
  • Leaked emails and phones could enable targeted phishing against officials.
Full article765 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini September 15, 2026

Japan ‘s Digital Agency disclosed a VPN breach exposing 246,000 government employee records across 23 ministries. Detected June 25, publicly disclosed September 11.

Japan ‘s Digital Agency disclosed that attackers exploited a vulnerability in a VPN device to access its Government Solution Service (GSS), potentially leaking personal information belonging to approximately 246,000 government employees, public officials, and contractors. The breach was detected on June 25 and confirmed as a VPN exploitation on July 9, meaning the public disclosure came 78 days after the initial detection and 63 days after the intrusion method was identified.

“It has come to our attention that, due to unauthorized external access, some files containing personal information handled on the Government Solution Service (GSS), operated by the Digital Agency, may have been leaked to an external party.” reads the advisory. “We have confirmed that the personal information that may have been leaked pertains to employees of various ministries and agencies that use GSS (hereinafter referred to as “GSS user organizations”) and those involved in their work, and does not include personal information of the general public.”

GSS connects 23 Japanese ministries and agencies through shared IT infrastructure. A breach of this platform could potentially affect many government organizations at once.

The attack followed a straightforward path. An outsider exploited a vulnerability in a VPN device that serves the GSS network, accessed the system using a maintenance and operations staff member’s account, and browsed a large number of files on the server. The agency detected the unusual activity on June 25, confirmed the VPN exploitation on July 9, then suspended the maintenance account and cut off external communications from the compromised hardware the same day. A subsequent investigation with external security specialists confirmed that files containing personal information may have been exfiltrated.

“On June 25, 2026, we detected that a large number of files on the server had been accessed using the account of a maintenance and operations staff member, and we began an investigation. On July 9, it was discovered that a third party had exploited a vulnerability in the network connection device (VPN) to infiltrate the system and gain unauthorized access. On the same day, we suspended the maintenance and operations staff member’s account and cut off communication between the compromised equipment and the outside world to prevent further unauthorized access.” continues the report.”As a result of our investigation with the cooperation of an external expert company, we have confirmed that there is a possibility that personal information may have been leaked to an external party.”

The potentially exposed data breaks down to roughly 236,000 names, 231,000 email addresses, 94,000 phone numbers, and approximately 1,000 physical addresses. Of the 246,000 total records, about 189,000 belong to employees of GSS-using organizations and public officials involved in their work, including staff at independent administrative agencies. The remaining 57,000 records relate to businesses and individuals contracted to support those organizations. The data doesn’t include My Number identification numbers, financial institution account numbers, or pension numbers.

The VPN flaw was rated medium severity and wasn’t a zero-day. A patch was already available when attackers exploited it, but the agency hasn’t revealed the VPN product or the flaw.

Japan’s privacy regulator was notified on July 15, six days after the attack was confirmed. The Digital Agency said the delay came from the difficulty of tracing the attack, assessing the affected data, and identifying those involved.

The incident also shows the risk of leaving a known, patchable flaw unaddressed on infrastructure shared by 23 ministries.

No confirmed misuse of the exposed data has been reported. However, the leaked names, email addresses and phone numbers could enable targeted phishing and social engineering, including scams impersonating Japan’s Digital Agency. The agency will contact affected people directly and warns that it will never request passwords or payments by email or phone.

The breach is one in a series of significant cybersecurity incidents affecting Japanese institutions. NISC, Japan’s National Cyber Incident Readiness and Strategy Center, disclosed a breach in 2023 that affected its email system. Japan Aerospace Exploration Agency (JAXA) reported unauthorized access to its systems in 2024. The pattern points to systemic challenges in patching and access management across Japan’s public sector infrastructure rather than isolated failures.

The Digital Agency’s planned remediation includes improved vulnerability management and changes to external connection methods, which are the right responses to the immediate incident. Whether they address the underlying governance question is harder to assess from the public advisory alone.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/199090/security/non-zero-day-vpn-flaw-left-japan-government-shared-network-platform-exposed-246000-records-at-risk.html