Patchable VPN flaw exposed ~246,000 records of Japanese government personnel across 23 ministries
Japan's Digital Agency says attackers exploited a medium-severity, non-zero-day VPN device vulnerability to access its Government Solution Service, potentially exposing personal data of about 246,000 government employees, officials, and contractors.
Japan's Digital Agency disclosed that a third party exploited a medium-severity, already-patchable (non-zero-day) vulnerability in a VPN device used by the Government Solution Service (GSS), a shared platform serving 23 ministries. Approximately 246,000 record rows were potentially exposed, including about 236,000 names, 231,000 email addresses, 94,000 phone numbers, and 1,000 physical addresses of government employees, officials, and associated businesses and contractors. No My Number IDs, bank account details, or pension numbers were included, and no misuse of the data has been detected so far. The intrusion was detected on June 25 and confirmed as VPN exploitation on July 9, the same day the compromised maintenance staff account was suspended and the affected hardware isolated; the agency notified Japan's Personal Information Protection Commission on July 15, with public disclosure coming 78 days after initial detection. The VPN product and specific flaw were not disclosed. Security Affairs notes the leaked emails and phone numbers could enable targeted phishing against officials.
- Medium-severity, non-zero-day (patchable) VPN device vulnerability exploited on Government Solution Service (GSS) shared platform used by 23 ministries
- ~246,000 record rows potentially exposed: ~236,000 names, ~231,000 email addresses, ~94,000 phone numbers, ~1,000 physical addresses
- Affected parties include government employees, officials, contractors, and associated businesses
- No My Number IDs, bank account details, or pension numbers exposed; no misuse of data detected so far
- Intrusion detected June 25; confirmed as VPN exploitation July 9; compromised staff account suspended and hardware isolated July 9
- Personal Information Protection Commission notified July 15; public disclosure came 78 days after initial detection
- VPN product and specific vulnerability not disclosed
Coverage timelineoldest first · each row is one article
- · 1d agoJapan's Digital Agency says VPN flaw exposed 246,000 personnel records
BleepingComputer· 70
Attackers exploited a VPN device vulnerability to breach Japan's Digital Agency, potentially exposing 246,000 records of government employees and officials.
- · 14h agoNon-Zero-Day VPN Flaw Left Japan ‘s Government Shared Network Platform Exposed: 246,000 Records at Risk
Security Affairs· 72
Japan's Digital Agency says attackers exploited a patchable VPN flaw to access a government shared platform, exposing records of ~246,000 employees across 23 ministries.