Japan’s Digital Agency Breach Exposes 240,000+ Users’ Personal Records to Hackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Japan’s Digital Agency has confirmed a significant data breach affecting the Government Solution Service (GSS), a shared IT platform used across multiple ministries and government bodies, after attackers exploited a vulnerability in a VPN appliance to gain unauthorized access to internal servers.

The agency disclosed on September 11 that approximately 246,000 personal records may have been exposed, making this one of the largest government data incidents reported in Japan this year.

Japan Digital Agency Data Breach

According to the agency’s official statement, suspicious activity was first detected on June 25, 2026, when a large volume of files on a GSS server were accessed using the credentials of a maintenance and operations staff member.

A deeper investigation, carried out with an external cybersecurity firm, traced the intrusion to a VPN device vulnerability that a third party exploited to infiltrate the network.

Investigators later determined the attacker had actually been active since late May, meaning the breach went undetected for nearly a month before discovery.

On July 9, once the entry point was confirmed, the agency suspended the compromised account and severed the affected equipment’s connection to external networks to contain further access.

Notably, security researchers reported that the exploited VPN flaw was rated medium severity, was not a zero-day, and a patch had already been publicly available before attackers took advantage of it, raising fresh questions about the agency’s patch management practices.

GSS unauthorized access overview (Image Source: digital.go.jp)

The compromised files reportedly contained names, email addresses, phone numbers, and physical addresses tied to roughly 189,000 employees and public officials from GSS user organizations, along with about 57,000 records belonging to contractors and businesses supporting those agencies, according to the official announcement published by Japan’s Digital Agency.

Broken down by data type, the exposure includes approximately 236,000 names, 231,000 email addresses, 94,000 phone numbers, and around 1,000 physical addresses, with some entries overlapping across categories.

The agency emphasized that no My Number identification data, bank account details, or pension information was included, and that data belonging to the general public was not affected.

The Digital Agency stated that no confirmed misuse of the leaked information has occurred so far, but warned that the exposed contact details could be leveraged in phishing campaigns impersonating the agency or affiliated organizations.

It urged affected individuals to remain cautious of unsolicited emails, calls, or text messages requesting passwords or financial information, clarifying that it will never request such details through these channels. Affected individuals will be contacted individually as identification efforts continue.

The agency has pledged to overhaul its vulnerability management processes and improve how external connections to government systems are secured to prevent similar incidents.

The roughly 78-day gap between initial detection and public disclosure has drawn scrutiny, underscoring broader concerns about the security of internet-facing VPN infrastructure used across government and enterprise networks worldwide

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post Japan’s Digital Agency Breach Exposes 240,000+ Users’ Personal Records to Hackers appeared first on Cyber Security News.