Japan’s Digital Agency has announced a major cybersecurity breach, impacting its Government Solution Service (GSS) platform. Hackers exploited a vulnerability within a VPN device, granting them unauthorized access to sensitive internal servers. This breach, confirmed on September 11, has potentially exposed the personal data of approximately 246,000 individuals, marking it as one of Japan’s most significant data security incidents this year.
Details of the Data Breach
The breach was first detected on June 25, 2026, when unusual activity was noted on a GSS server. Intruders accessed a large volume of files using the login credentials of a maintenance worker. An external cybersecurity firm was enlisted to assist with the investigation, which traced the intrusion back to a vulnerable VPN device. This flaw was exploited by a third party to penetrate the network, with the breach beginning in late May and remaining undetected for nearly a month.
Upon identification of the breach entry point on July 9, the Digital Agency took swift action by disabling the compromised account and disconnecting affected equipment from external networks to prevent further unauthorized access. The exploited VPN vulnerability, which had a medium severity rating, was already known and had been patched, raising concerns about the agency’s patch management practices.
Impact and Data Details
The compromised data includes names, email addresses, phone numbers, and physical addresses of approximately 189,000 government employees and public officials, along with 57,000 records associated with contractors and supporting businesses. In total, about 236,000 names, 231,000 email addresses, 94,000 phone numbers, and 1,000 physical addresses were exposed. However, no My Number identification, bank account, or pension information was compromised, and the general public’s data remains unaffected.
The Digital Agency has confirmed that there has been no misuse of the leaked data to date. However, they caution that the exposed contact information could be used in phishing attempts impersonating government entities. Affected individuals are advised to be wary of unsolicited communications asking for passwords or financial details, which the agency will never request through these channels.
Future Security Measures
In response to this breach, the Digital Agency has committed to strengthening its vulnerability management and securing external connections to government systems to prevent future incidents. The 78-day delay between initial breach detection and public disclosure has drawn criticism, highlighting broader issues regarding the security of internet-facing VPN infrastructure worldwide.
In the wake of this incident, the agency is working to contact affected individuals and improve its cybersecurity measures to safeguard sensitive information moving forward.
