ZeroHour
SecurityWeekpublished ()ingested Ionut Arghire
Part of a story covered by 2 sources: “Japan's Digital Agency Breach: VPN Flaw and Misused Maintenance Account Expose ~246,000 Records on ~240,000 People” — merged summary and timeline →

240,000 Hit by Data Breach at Japan’s Digital Agency

highData breach exploited in the wildimportance 65
AI summary · glm-5.3

Japan's Digital Agency says hackers exploited a VPN flaw and a maintenance account to steal ~246,000 records on 240,000 people.

Japan's Digital Agency disclosed a breach of its Government Solution Service (GSS) affecting roughly 240,000 individuals, discovered in late June. Attackers exploited a publicly disclosed vulnerability in a VPN product and used a maintenance and operations employee's account to access over 246,000 records, including names (~236,000), email addresses (~231,000), phone numbers (~94,000), and addresses (~1,000). The agency blocked external access to the affected server, suspended the account, and said no ID numbers or financial account data were compromised.

  • ~246,000 records on ~240,000 GSS users, officials and businesses accessed
  • Publicly disclosed VPN product vulnerability exploited as entry point
  • Maintenance employee's account used to access files
  • Server access blocked and compromised account suspended
Full article281 words · extracted from securityweek.com · click to collapse

Japan’s Digital Agency has disclosed a data breach affecting the personal information of approximately 240,000 individuals.

The incident, it says, was discovered in late June, after the hackers accessed files from its Government Solution Service (GSS) using a maintenance and operations employee’s account.

In July, the investigation determined that a vulnerability in a VPN product had been exploited to access the system.

According to the agency, the attackers compromised over 246,000 records containing names (approximately 236,000), addresses (~1,000), email addresses (~231,000), and phone numbers (~94,000).

The compromised information, it says, belongs to users, public officials, administrative staff, and businesses and individuals working with GSS.

The leaked information had been provided by every individual when applying to use GSS, and most of the addresses and phone numbers are associated with the individuals’ workplace, namely a government building or an office, the agency explains in an accompanying FAQ.

Advertisement. Scroll to continue reading.

Other personal information, such as individual identification numbers and financial account information, was not affected.

Japan’s Digital Agency blocked external access to the affected server and suspended the employee account used in the attack immediately after confirming the exploitation.

While it did not name the exploited VPN product, it said it would strengthen vulnerability management, as the targeted vulnerability had already been publicly disclosed before the attack was confirmed.

No other systems were compromised in the attack, and no information of the general public was compromised, the agency said.

Related: Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack

Related: Personal, Financial Info Exposed in Revolut Data Breach

Related: Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack

Related: Surfshark Systems Targeted by Hackers

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/240000-hit-by-data-breach-at-japans-digital-agency/