ZeroHour
BleepingComputerpublished ()ingested Bill Toulas
Part of a story covered by 2 sources: “Patchable VPN flaw exposed ~246,000 records of Japanese government personnel across 23 ministries” — merged summary and timeline →

Japan's Digital Agency says VPN flaw exposed 246,000 personnel records

highData breach exploited in the wildimportance 70
AI summary · glm-5.3

Attackers exploited a VPN device vulnerability to breach Japan's Digital Agency, potentially exposing 246,000 records of government employees and officials.

Japan's Digital Agency disclosed that a third party exploited a medium-severity, non-zero-day vulnerability in a VPN device used by the Government Solution Service (GSS) to gain unauthorized access. Around 246,000 record rows were potentially exposed, including 236,000 names, 231,000 email addresses, 94,000 phone numbers, and 1,000 physical addresses of government employees and associated businesses. No My Number IDs, bank account details, or pension numbers were exposed, and no misuse of the data has been detected so far. The agency suspended the compromised staff account on July 9 and notified Japan's Personal Information Protection Commission on July 15.

  • VPN device flaw gave attackers access to Japan's Government Solution Service system
  • ~246,000 rows exposed: names, emails, phone numbers, addresses of officials
  • No My Number, bank, or pension data leaked; no misuse detected yet
  • Flaw rated medium severity, not a zero-day; VPN product undisclosed
Full article441 words · extracted from bleepingcomputer.com · click to collapse

Japan's Digital Agency says VPN flaw exposed 246,000 personnel records

Japan’s Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees.

The agency says that the attacker gained initial access by exploiting a vulnerability in a VPN device used by the Government Solution Service (GSS).

An investigation started on June 25, after the agency detected a large-scale file access from the account of a maintenance and operations staff member.

“On July 9th, it was discovered that a third party had used a vulnerability in a network-connected device (VPN) to gain access to the system and gain unauthorized access,” reads the announcement.

“On the same day, we suspended the account of the maintenance and operations personnel in question, cut off communication between the compromised equipment and the outside world, and prevented further unauthorized access.”

It is unclear what VPN product was affected or the vulnerability exploited in the breach. However, the Japanese agency said in a separate Q&A that the issue had a medium severity rating and was not a zero-day.

The investigation revealed that the following data may have been exposed:

  • 236,000 names
  • 231,000 email addresses
  • 94,000 telephone numbers
  • 1,000 physical addresses

Exposed individuals include government employees, public officials, and associated businesses and individuals who use the GSS system.

However, the incident did not expose personal data of the general public, and the potentially compromised information does not include My Number identification numbers, bank-account details, or pension numbers.

Also, the agency has not detected any cases of actual misuse of the impacted information, but still warned  about the elevated risk of impersonation and phishing, urging people not to open links or attachments in unsolicited communications.

The Digital Agency reminded people that it will never ask for passwords or credit card information via email or phone.

Affected individuals will be contacted directly, and the agency also set up a dedicated support line.

The agency notified Japan’s Personal Information Protection Commission on July 15, and clarified that the delay in disclosing the incident to the public was due to the complexity of determining the intrusion path, identifying potentially affected information, and establishing who was affected.

The agency says the impact was limited to the affected system, with no confirmed unauthorized access, data leakage, or comparable breaches affecting other systems. It also noted that the incident and response operations didn’t impact government services availability.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.bleepingcomputer.com/news/security/japans-digital-agency-says-vpn-flaw-exposed-246-000-personnel-records/