Japan’s Digital Agency has disclosed a data breach that may have exposed roughly 246,000 rows of personal information belonging to government employees, public officials, and associated businesses using the Government Solution Service (GSS).
The agency traced initial access to a vulnerability in a network-connected VPN device used by GSS. In a Q&A accompanying the disclosure, the agency described the flaw as medium severity and confirmed it was not a zero-day at the time of exploitation, though it has not named the affected VPN product or the specific vulnerability.
The investigation began on June 25 after the agency flagged unusually large-scale file access originating from the account of a maintenance and operations staff member. By July 9, the agency determined that a third party had abused the VPN flaw to gain unauthorized system access. That day, it suspended the compromised staff account, severed the affected equipment’s connection to external networks, and blocked further unauthorized activity.
What Was Exposed
- Approximately 236,000 names
- 231,000 email addresses
- 94,000 telephone numbers
- 1,000 physical addresses
The exposed data covers government employees, public officials, and individuals or businesses connected to the GSS platform. The agency emphasized that general public data was not involved, and that no My Number identification numbers, bank account details, or pension information were part of the breach.
No confirmed misuse of the exposed data has been detected so far, but the agency warned of heightened risk from impersonation and phishing attempts, urging recipients of unsolicited messages to avoid clicking links or opening attachments. It reiterated that it will never request passwords or payment card details by email or phone, and said it will contact affected individuals directly while operating a dedicated support hotline.
Disclosure Timeline
Japan’s Personal Information Protection Commission was notified on July 15. The agency attributed the gap between discovery and public disclosure to the complexity of tracing the intrusion path, identifying the full scope of exposed data, and confirming which individuals were affected.
The Digital Agency stated the breach was contained to the single affected system, with no evidence of lateral movement, additional data leakage, or comparable incidents elsewhere in its infrastructure. It also confirmed that government service availability was not disrupted during the incident or the response.
