Japan's Digital Agency Breach: VPN Flaw and Misused Maintenance Account Expose ~246,000 Records on ~240,000 People
Attackers exploited a medium-severity, already-patched VPN appliance vulnerability and a maintenance employee's credentials to access roughly 246,000 records on Japan's Digital Agency's shared Government Solution Service (GSS), affecting about 240,000 people.
Japan's Digital Agency disclosed a breach of its Government Solution Service (GSS), a shared IT platform used across ministries, affecting approximately 240,000 individuals and over 246,000 records. The attacker was active since late May, entering by exploiting a publicly disclosed vulnerability in a VPN product — described as medium severity with a patch already available — and using a maintenance and operations employee's account credentials. Suspicious activity was detected on June 25, external access to the affected server was blocked, the compromised account was suspended, and containment was completed on July 9; public disclosure came on September 11. Exposed data includes names (~236,000), email addresses (~231,000), phone numbers (~94,000), and addresses (~1,000), spanning roughly 189,000 employees/public officials and 57,000 contractors. The agency said no My Number, ID numbers, financial account, bank, or pension data was compromised, and no misuse of the data has been confirmed. The 78-day gap between detection and public disclosure has drawn scrutiny over patch management.
- ~246,000 records on ~240,000 people exposed via the Government Solution Service (GSS), a shared cross-ministry IT platform
- Entry point: publicly disclosed, medium-severity VPN appliance vulnerability for which a patch was already available
- Attacker used a maintenance and operations employee's account credentials; active since late May
- Suspicious activity detected June 25; external server access blocked, account suspended, containment completed July 9; disclosed publicly September 11
- Exposed data: names (~236,000), email addresses (~231,000), phone numbers (~94,000), addresses (~1,000)
- Affected population: ~189,000 employees/public officials and ~57,000 contractors
- No My Number, ID number, bank/financial account, or pension data compromised; no confirmed misuse to date
- 78-day detection-to-disclosure gap has drawn scrutiny over patch management
Coverage timelineoldest first · each row is one article
- · 10h ago240,000 Hit by Data Breach at Japan’s Digital Agency
SecurityWeek· 65
Japan's Digital Agency says hackers exploited a VPN flaw and a maintenance account to steal ~246,000 records on 240,000 people.
- · 7h agoJapan’s Digital Agency Breach Exposes 240,000+ Users’ Personal Records to Hackers
Cyber Security News· 72
Attackers exploited a patched VPN appliance flaw to breach Japan's Digital Agency shared government platform, exposing about 246,000 personal records.