ZeroHour
Story · 2 sources · 2 articlesfirst updated ()1

Japan's Digital Agency Breach: VPN Flaw and Misused Maintenance Account Expose ~246,000 Records on ~240,000 People

highData breachexploited in the wildimportance 72
What's new: First merged summary: combined SecurityWeek and Cyber Security News reports on the Japan Digital Agency breach into a single story, reconciling overlapping details (record counts, data types, timeline, and affected groups) and incorporating report 2's additional specifics on VPN flaw severity, attacker dwell time, containment dates, and disclosure timeline.
Merged summary · glm-5.3 · rewritten as coverage arrives

Attackers exploited a medium-severity, already-patched VPN appliance vulnerability and a maintenance employee's credentials to access roughly 246,000 records on Japan's Digital Agency's shared Government Solution Service (GSS), affecting about 240,000 people.

Japan's Digital Agency disclosed a breach of its Government Solution Service (GSS), a shared IT platform used across ministries, affecting approximately 240,000 individuals and over 246,000 records. The attacker was active since late May, entering by exploiting a publicly disclosed vulnerability in a VPN product — described as medium severity with a patch already available — and using a maintenance and operations employee's account credentials. Suspicious activity was detected on June 25, external access to the affected server was blocked, the compromised account was suspended, and containment was completed on July 9; public disclosure came on September 11. Exposed data includes names (~236,000), email addresses (~231,000), phone numbers (~94,000), and addresses (~1,000), spanning roughly 189,000 employees/public officials and 57,000 contractors. The agency said no My Number, ID numbers, financial account, bank, or pension data was compromised, and no misuse of the data has been confirmed. The 78-day gap between detection and public disclosure has drawn scrutiny over patch management.

  • ~246,000 records on ~240,000 people exposed via the Government Solution Service (GSS), a shared cross-ministry IT platform
  • Entry point: publicly disclosed, medium-severity VPN appliance vulnerability for which a patch was already available
  • Attacker used a maintenance and operations employee's account credentials; active since late May
  • Suspicious activity detected June 25; external server access blocked, account suspended, containment completed July 9; disclosed publicly September 11
  • Exposed data: names (~236,000), email addresses (~231,000), phone numbers (~94,000), addresses (~1,000)
  • Affected population: ~189,000 employees/public officials and ~57,000 contractors
  • No My Number, ID number, bank/financial account, or pension data compromised; no confirmed misuse to date
  • 78-day detection-to-disclosure gap has drawn scrutiny over patch management

Coverage timeline

  1. · 10h ago
    SecurityWeek· 65
    240,000 Hit by Data Breach at Japan’s Digital Agency

    Japan's Digital Agency says hackers exploited a VPN flaw and a maintenance account to steal ~246,000 records on 240,000 people.

  2. · 7h ago
    Cyber Security News· 72
    Japan’s Digital Agency Breach Exposes 240,000+ Users’ Personal Records to Hackers

    Attackers exploited a patched VPN appliance flaw to breach Japan's Digital Agency shared government platform, exposing about 246,000 personal records.