Japan's Digital Agency has disclosed a data breach involving approximately 246,000 record rows with personal information belonging to government employees. The intrusion occurred through exploitation of a vulnerability in a VPN device operated by the Government Solution Service (GSS).
Detection began on June 25 when the agency identified unusual file access activity originating from a maintenance and operations staff account. On July 9, investigators confirmed that an unauthorized third party had leveraged a network-connected device vulnerability to gain system access.
On July 9th, it was discovered that a third party had used a vulnerability in a network-connected device (VPN) to gain access to the system and gain unauthorized access. On the same day, we suspended the account of the maintenance and operations personnel in question, cut off communication between the compromised equipment and the outside world, and prevented further unauthorized access.
Japan's Digital Agency
The specific VPN product and vulnerability remain unidentified in public disclosures. The Digital Agency characterized the flaw as medium severity and confirmed it was not a zero-day vulnerability.
The breach exposed the following categories of information:
- 236,000 names
- 231,000 email addresses
- 94,000 telephone numbers
- 1,000 physical addresses
Affected parties encompass government employees, public officials, and businesses and individuals utilizing the GSS system. The incident did not compromise data of the general public, and sensitive identifiers such as My Number identification numbers, banking details, or pension information remained unexposed.
While no confirmed cases of data misuse have been detected, the agency warned of heightened risks for impersonation and phishing attacks. Officials advised recipients to avoid opening unsolicited links or attachments and reminded the public that legitimate agency communications never request passwords or credit card details through email or telephone.
Impacted individuals will receive direct notification, and the agency established a dedicated support hotline. The Personal Information Protection Commission was notified on July 15. The agency attributed the delay in public disclosure to the time required to trace the intrusion path, catalog affected data, and identify all impacted individuals.
The Digital Agency stated that the breach remained confined to the affected system with no evidence of unauthorized access, data exfiltration, or similar compromises on other infrastructure. Government service availability was not disrupted by the incident or response operations.