Japan's Digital Agency has confirmed that an attacker reached systems holding personal information on government employees and officials by exploiting a vulnerability in a VPN appliance used by the Government Solution Service (GSS), in a breach it says may have exposed around 246,000 record rows. The agency began investigating on 25 June after detecting large-scale file access from the account of a maintenance and operations staff member; on 9 July it confirmed that a third party had used a vulnerability in a network-connected VPN device to gain unauthorised access, suspended the account, cut off communication between the compromised equipment and the outside world, and prevented further access. The exposed data is granular and directly identifying: approximately 236,000 names, 231,000 email addresses, 94,000 telephone numbers and 1,000 physical addresses drawn from government employees, public officials and the businesses and individuals that use the GSS system. The agency says the personal data of the general public was not involved and that My Number identifiers, bank account details and pension numbers were not exposed, and it has detected no misuse to date while warning of elevated impersonation and phishing risk. The disclosure timeline is the analytically important part: the agency notified Japan's Personal Information Protection Commission on 15 July but published only on 11โ14 September, attributing the delay to the complexity of determining the intrusion path, identifying the affected information and establishing who was affected. It has confirmed the incident was contained to the affected system, did not affect government service availability in the operational sense, and โ critically for how defenders should read it โ has stated through a separate Q&A that the exploited VPN flaw was rated medium severity and was not a zero-day. The agency has not named the VPN product or the vulnerability, affected individuals are being contacted directly, and a dedicated support line has been established.
| Attribute | Detail |
|---|---|
| Sector | Government |
| Date | 2026-09-15 |
| Source | BleepingComputer |
| Reliability | Tier 2 |