Japan’s Digital Agency Breach Exposes 240,000+ Users’ Personal Records to Hackers
Attackers exploited a patched VPN appliance flaw to breach Japan's Digital Agency shared government platform, exposing about 246,000 personal records.
Japan's Digital Agency disclosed on September 11 that attackers exploited a VPN appliance vulnerability to access the Government Solution Service (GSS), a shared IT platform across ministries, exposing roughly 246,000 personal records. The attacker was active since late May using a maintenance staffer's credentials, with suspicious activity detected June 25 and containment on July 9. Exposed data covers about 189,000 employees/public officials and 57,000 contractors; no My Number, bank, or pension data was included. The VPN flaw was medium severity with a patch already available, and the 78-day detection-to-disclosure gap has drawn scrutiny.
- Patched medium-severity VPN flaw enabled intrusion into shared government platform
- ~246,000 records exposed: 189,000 officials, 57,000 contractors
- Attacker active since late May using staff credentials; contained July 9
- No My Number or bank data affected; no confirmed misuse so far
- 78-day gap between detection and public disclosure raises patch-management scrutiny
Full article529 words · extracted from cybersecuritynews.com · click to collapse
Japan’s Digital Agency has confirmed a significant data breach affecting the Government Solution Service (GSS), a shared IT platform used across multiple ministries and government bodies, after attackers exploited a vulnerability in a VPN appliance to gain unauthorized access to internal servers.
The agency disclosed on September 11 that approximately 246,000 personal records may have been exposed, making this one of the largest government data incidents reported in Japan this year.
Japan Digital Agency Data Breach
According to the agency’s official statement, suspicious activity was first detected on June 25, 2026, when a large volume of files on a GSS server were accessed using the credentials of a maintenance and operations staff member.
A deeper investigation, carried out with an external cybersecurity firm, traced the intrusion to a VPN device vulnerability that a third party exploited to infiltrate the network.
Investigators later determined the attacker had actually been active since late May, meaning the breach went undetected for nearly a month before discovery.
On July 9, once the entry point was confirmed, the agency suspended the compromised account and severed the affected equipment’s connection to external networks to contain further access.
Notably, security researchers reported that the exploited VPN flaw was rated medium severity, was not a zero-day, and a patch had already been publicly available before attackers took advantage of it, raising fresh questions about the agency’s patch management practices.

The compromised files reportedly contained names, email addresses, phone numbers, and physical addresses tied to roughly 189,000 employees and public officials from GSS user organizations, along with about 57,000 records belonging to contractors and businesses supporting those agencies, according to the official announcement published by Japan’s Digital Agency.
Broken down by data type, the exposure includes approximately 236,000 names, 231,000 email addresses, 94,000 phone numbers, and around 1,000 physical addresses, with some entries overlapping across categories.
The agency emphasized that no My Number identification data, bank account details, or pension information was included, and that data belonging to the general public was not affected.
The Digital Agency stated that no confirmed misuse of the leaked information has occurred so far, but warned that the exposed contact details could be leveraged in phishing campaigns impersonating the agency or affiliated organizations.
It urged affected individuals to remain cautious of unsolicited emails, calls, or text messages requesting passwords or financial information, clarifying that it will never request such details through these channels. Affected individuals will be contacted individually as identification efforts continue.
The agency has pledged to overhaul its vulnerability management processes and improve how external connections to government systems are secured to prevent similar incidents.
The roughly 78-day gap between initial detection and public disclosure has drawn scrutiny, underscoring broader concerns about the security of internet-facing VPN infrastructure used across government and enterprise networks worldwide
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/japan-digital-agency-data-breach/