[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f6A8sNxs5sP37ot4M5uoZ3N1aBQ6IHyXDGeAY4B6IuKY":3},{"article":4,"iocs":48},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":27,"category":28,"article_tags":32},"6da3a40a-d985-438a-9d08-0dfb0a2fd399","240,000 Hit by Data Breach at Japan’s Digital Agency","240-000-hit-by-data-breach-at-japan-s-digital-agency-19fce4","Hackers exploited a vulnerability in a VPN product to steal the personal information of roughly 240,000 people. The post 240,000 Hit by Data Breach at Japan’s Digital Agency appeared first on SecurityWeek.","Japan's Digital Agency disclosed a data breach affecting approximately 240,000 individuals after hackers exploited a known VPN vulnerability to compromise a maintenance employee's account. The attackers accessed the Government Solution Service (GSS) and stole names, addresses, email addresses, and phone numbers of users, officials, and businesses working with GSS. The agency has since blocked external access and suspended the compromised account, though the specific VPN product exploited was not named.","Japan's Digital Agency suffers breach of 240,000 records via exploited VPN vulnerability.","Japan’s Digital Agency has disclosed a data breach affecting the personal information of approximately 240,000 individuals. The incident, it says, was discovered in late June, after the hackers accessed files from its Government Solution Service (GSS) using a maintenance and operations employee’s account. In July, the investigation determined that a vulnerability in a VPN product had been exploited to access the system. According to the agency, the attackers compromised over 246,000 records containing names (approximately 236,000), addresses (~1,000), email addresses (~231,000), and phone numbers (~94,000). The compromised information, it says, belongs to users, public officials, administrative staff, and businesses and individuals working with GSS. The leaked information had been provided by every individual when applying to use GSS, and most of the addresses and phone numbers are associated with the individuals’ workplace, namely a government building or an office, the agency explains in an accompanying FAQ.Advertisement. Scroll to continue reading. Other personal information, such as individual identification numbers and financial account information, was not affected. Japan’s Digital Agency blocked external access to the affected server and suspended the employee account used in the attack immediately after confirming the exploitation. While it did not name the exploited VPN product, it said it would strengthen vulnerability management, as the targeted vulnerability had already been publicly disclosed before the attack was confirmed. No other systems were compromised in the attack, and no information of the general public was compromised, the agency said. Related: Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack Related: Personal, Financial Info Exposed in Revolut Data Breach Related: Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack Related: Surfshark Systems Targeted by Hackers Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code ExecutionThree JFrog Artifactory Flaws Exploited for Backdoor DeploymentConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like AttacksBlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-DaysGitLab Vulnerability Exploited One Day After DisclosureCheck Point Patches Critical VPN VulnerabilitiesSurfshark Systems Targeted by HackersPaperCut Flaws Exploited in AI-Powered Attacks Latest News Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety ConstraintsHacked HBO Max Reddit Account Used for Malware Delivery via ClickFix AttackRoot RCE Zero-Day in Cisco Secure Email Gateway Under Active ExploitationBeijing Hits Back at Anthropic CEO’s Call to Curb China’s AI DevelopmentNew Warnings About the Risks of AI to Humanity Revive a Long-Running DebatePersonal, Financial Info Exposed in Revolut Data BreachThe Race to Control AI and Protect What Makes Us Human Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveZero Networks has named Yossi Dagan as Chief Financial Officer.Manifold has appointed Joe Sullivan to its Board of Directors.Patrick McKinney has joined Turing as Chief Information Security Officer.More People On The MoveExpert Insights This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, \"data\" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002F240000-hit-by-data-breach-at-japans-digital-agency\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2026\u002F09\u002FJapan.jpeg","2026-09-15T11:45:31+00:00","2026-09-15T12:00:19.13534+00:00",7,[18,21,24],{"name":19,"type":20},"Japan's Digital Agency","vendor",{"name":22,"type":23},"Government Solution Service (GSS)","product",{"name":25,"type":26},"VPN","technology","2e06f76c-d5b9-4f54-9eef-4d3447b10730",{"id":27,"icon":29,"name":30,"slug":31},null,"Breaches","breaches",[33,38,43],{"category":34},{"id":35,"icon":29,"name":36,"slug":37},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":39},{"id":40,"icon":29,"name":41,"slug":42},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",{"category":44},{"id":45,"icon":29,"name":46,"slug":47},"c5c77cdb-f7d7-4990-9436-c81dcbff1163","Policy","policy",[]]