ZeroHour
Story · 2 sources · 2 articlesfirst updated ()

Patchable VPN flaw exposed ~246,000 records of Japanese government personnel across 23 ministries

highData breachexploited in the wildimportance 72
What's new: This is the first merged summary of the story. Both reports agree on all core facts; Security Affairs adds that the incident affected a shared platform spanning 23 ministries, provides the detection date (June 25) and the 78-day gap until public disclosure, notes the compromised hardware was isolated, and highlights phishing risk from the exposed contact data. BleepingComputer uniquely reports…
Merged summary · glm-5.3 · rewritten as coverage arrives

Japan's Digital Agency says attackers exploited a medium-severity, non-zero-day VPN device vulnerability to access its Government Solution Service, potentially exposing personal data of about 246,000 government employees, officials, and contractors.

Japan's Digital Agency disclosed that a third party exploited a medium-severity, already-patchable (non-zero-day) vulnerability in a VPN device used by the Government Solution Service (GSS), a shared platform serving 23 ministries. Approximately 246,000 record rows were potentially exposed, including about 236,000 names, 231,000 email addresses, 94,000 phone numbers, and 1,000 physical addresses of government employees, officials, and associated businesses and contractors. No My Number IDs, bank account details, or pension numbers were included, and no misuse of the data has been detected so far. The intrusion was detected on June 25 and confirmed as VPN exploitation on July 9, the same day the compromised maintenance staff account was suspended and the affected hardware isolated; the agency notified Japan's Personal Information Protection Commission on July 15, with public disclosure coming 78 days after initial detection. The VPN product and specific flaw were not disclosed. Security Affairs notes the leaked emails and phone numbers could enable targeted phishing against officials.

  • Medium-severity, non-zero-day (patchable) VPN device vulnerability exploited on Government Solution Service (GSS) shared platform used by 23 ministries
  • ~246,000 record rows potentially exposed: ~236,000 names, ~231,000 email addresses, ~94,000 phone numbers, ~1,000 physical addresses
  • Affected parties include government employees, officials, contractors, and associated businesses
  • No My Number IDs, bank account details, or pension numbers exposed; no misuse of data detected so far
  • Intrusion detected June 25; confirmed as VPN exploitation July 9; compromised staff account suspended and hardware isolated July 9
  • Personal Information Protection Commission notified July 15; public disclosure came 78 days after initial detection
  • VPN product and specific vulnerability not disclosed

Coverage timeline

  1. · 1d ago
    BleepingComputer· 70
    Japan's Digital Agency says VPN flaw exposed 246,000 personnel records

    Attackers exploited a VPN device vulnerability to breach Japan's Digital Agency, potentially exposing 246,000 records of government employees and officials.

  2. · 14h ago
    Security Affairs· 72
    Non-Zero-Day VPN Flaw Left Japan ‘s Government Shared Network Platform Exposed: 246,000 Records at Risk

    Japan's Digital Agency says attackers exploited a patchable VPN flaw to access a government shared platform, exposing records of ~246,000 employees across 23 ministries.