Japan's Digital Agency says VPN flaw exposed 246,000 personnel records
Japan's Digital Agency reports VPN flaw exposed 246,000 government personnel records.
Summary
Japan's Digital Agency has disclosed a data breach affecting approximately 246,000 government employee records, resulting from a vulnerability in a VPN device used by the Government Solution Service (GSS). The breach was detected on June 25, with unauthorized access confirmed on July 9th. While the specific VPN product and vulnerability are not disclosed, the agency stated it was of medium severity and not a zero-day. The exposed data includes names, email addresses, and phone numbers, but not sensitive identification or financial details. The agency has notified Japan's Personal Information Protection Commission and is contacting affected individuals.
Full text
Japan's Digital Agency says VPN flaw exposed 246,000 personnel records By Bill Toulas September 14, 2026 04:36 PM 0 Japan’s Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees. The agency says that the attacker gained initial access by exploiting a vulnerability in a VPN device used by the Government Solution Service (GSS). An investigation started on June 25, after the agency detected a large-scale file access from the account of a maintenance and operations staff member. “On July 9th, it was discovered that a third party had used a vulnerability in a network-connected device (VPN) to gain access to the system and gain unauthorized access,” reads the announcement. “On the same day, we suspended the account of the maintenance and operations personnel in question, cut off communication between the compromised equipment and the outside world, and prevented further unauthorized access.” It is unclear what VPN product was affected or the vulnerability exploited in the breach. However, the Japanese agency said in a separate Q&A that the issue had a medium severity rating and was not a zero-day. The investigation revealed that the following data may have been exposed: 236,000 names 231,000 email addresses 94,000 telephone numbers 1,000 physical addresses Exposed individuals include government employees, public officials, and associated businesses and individuals who use the GSS system. However, the incident did not expose personal data of the general public, and the potentially compromised information does not include My Number identification numbers, bank-account details, or pension numbers. Also, the agency has not detected any cases of actual misuse of the impacted information, but still warned about the elevated risk of impersonation and phishing, urging people not to open links or attachments in unsolicited communications. The Digital Agency reminded people that it will never ask for passwords or credit card information via email or phone. Affected individuals will be contacted directly, and the agency also set up a dedicated support line. The agency notified Japan’s Personal Information Protection Commission on July 15, and clarified that the delay in disclosing the incident to the public was due to the complexity of determining the intrusion path, identifying potentially affected information, and establishing who was affected. The agency says the impact was limited to the affected system, with no confirmed unauthorized access, data leakage, or comparable breaches affecting other systems. It also noted that the incident and response operations didn’t impact government services availability. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat Related Articles: Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentSouth Korea discloses data breach impacting diplomats worldwideArtifactory flaws chained in attacks deploying backdoor malwareCisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacksMagento StyleSmuggler zero-day exploited to deploy Linux backdoor