Japan Digital Agency Breach Exposes 240K+ User Records
Key Takeaways Japan’s Digital Agency confirmed a data breach affecting its Government Solution Service (GSS), a shared IT platform. Over 246,000 personal records, including names, email addresses,...
Key Takeaways
- Japan’s Digital Agency confirmed a data breach affecting its Government Solution Service (GSS), a shared IT platform.
- Over 246,000 personal records, including names, email addresses, and phone numbers of government employees, officials, and contractors, were exposed.
- The breach stemmed from the exploitation of a known vulnerability in a VPN appliance, for which a patch was already available.
- No My Number, bank account, or pension data was compromised, and the general public’s data remains unaffected.
- The agency detected the intrusion in late June 2026 but determined the attacker had been active since late May, leading to a nearly month-long undetected presence.
Japan’s Digital Agency Confirms Major Data Breach Affecting Government Solution Service
Japan’s Digital Agency has officially confirmed a significant data breach impacting its Government Solution Service (GSS), a critical IT platform shared by various government ministries and bodies. The incident, which came to light after attackers leveraged a vulnerability in a VPN appliance to gain unauthorized access to internal servers, exposed over 246,000 personal records.
Table Of Content
On September 11, the agency disclosed the extent of the compromise, identifying it as one of the largest government data incidents reported in Japan this year. The breach primarily affected records associated with government personnel and contractors.
Intrusion Details and Response
According to an official statement published by Japan’s Digital Agency, suspicious activity was first observed on June 25, 2026. Investigators noted a substantial volume of files being accessed on a GSS server using the credentials of a maintenance and operations staff member. A subsequent in-depth investigation, conducted with the assistance of an external cybersecurity firm, pinpointed the entry point to a vulnerability within a VPN device. A third party had exploited this flaw to penetrate the network.
Further analysis revealed that the attacker’s presence within the network dated back to late May, indicating that the breach remained undetected for nearly a month. By July 9, after confirming the precise entry vector, the Digital Agency took decisive action: the compromised account was suspended, and the affected equipment’s connection to external networks was severed to contain any further unauthorized access.
Of particular concern, cybersecurity researchers have pointed out that the exploited VPN vulnerability was not a zero-day and carried a medium severity rating. Crucially, a patch addressing this flaw had been publicly available prior to the attack, raising questions about the agency’s adherence to best practices in patch management.
Scope of Data Exposure
The compromised files contained a range of sensitive personal information. Approximately 189,000 employees and public officials from GSS user organizations had their names, email addresses, phone numbers, and physical addresses exposed. Additionally, about 57,000 records belonging to contractors and businesses supporting these agencies were also affected.
A detailed breakdown of the exposed data indicates approximately 236,000 names, 231,000 email addresses, 94,000 phone numbers, and around 1,000 physical addresses. It’s important to note that some entries might overlap across these categories. The Digital Agency emphasized that no My Number identification data, bank account details, or pension information was compromised, and data belonging to the general public was not affected by this incident.
Mitigation and Future Actions
While the Digital Agency has stated that there is no confirmed evidence of the leaked information being misused so far, it issued a warning regarding the potential for exposed contact details to be utilized in sophisticated phishing campaigns. These campaigns could impersonate the agency or its affiliated organizations.
The agency has urged all affected individuals to exercise extreme caution regarding unsolicited emails, calls, or text messages that request passwords or financial information. It explicitly clarified that it will never solicit such sensitive details through these communication channels. Efforts are ongoing to individually identify and contact all affected parties.
In response to the breach, the Digital Agency has committed to a comprehensive overhaul of its vulnerability management processes. It also plans to significantly improve the security protocols governing external connections to government systems, aiming to prevent similar incidents in the future. The approximately 78-day interval between the initial detection and public disclosure of the breach has drawn considerable scrutiny, highlighting broader concerns about the security posture of internet-facing VPN infrastructure across government and enterprise networks globally.
What You Should Do
- Exercise Caution: Be highly vigilant for any unsolicited emails, phone calls, or text messages, especially those claiming to be from the Digital Agency or other government entities.
- Verify Requests: Never provide personal or financial information in response to unexpected requests. Always verify the legitimacy of such communications through official, known contact channels.
- Report Suspicious Activity: If you receive any suspicious communications, report them to the appropriate authorities or the Digital Agency directly.
- Update Credentials: While not explicitly stated as compromised, consider updating passwords for any government-related accounts, especially if you reused passwords across different services.
- Enable Multi-Factor Authentication (MFA): Where available, enable MFA on all accounts to add an extra layer of security.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.