Japan's Digital Agency says VPN flaw exposed about 246,000 personnel records
Japan's Digital Agency disclosed that attackers exploited a vulnerability in a VPN product to access its Government Solution Service and steal personal information belonging to roughly 240,000 people, using a maintenance employee's account.
- Victim
- Digital Agency of Japan
- records
- 246.0K
On 11 September 2026, Japan's Digital Agency β the central government body created to modernise the country's public-sector IT β disclosed that attackers may have leaked the personal information of roughly 240,000 people. The agency said intruders had exploited a vulnerability in a VPN product to access files in its Government Solution Service (GSS), using the account of a maintenance and operations employee. The initial intrusion was traced back to late June 2026, and a July investigation determined that the VPN flaw had been used to reach the system.
Subsequent reporting put the exposure at more than 246,000 records, comprising approximately 236,000 names, around 1,000 addresses, roughly 231,000 email addresses and about 94,000 phone numbers. The agency noted that the targeted vulnerability had already been publicly disclosed before the attack was confirmed, underscoring a familiar failure mode in which a known, patchable flaw is exploited before remediation.
Rapid containment of a government platform
The Digital Agency said it had blocked external access to the affected server and suspended the employee account used in the attack immediately after confirming the exploitation. It framed the breach as confined to data reachable through the GSS platform via the compromised VPN path rather than a broader compromise of unrelated government systems.
For a government agency whose remit is to make public services more digital and trustworthy, a breach originating in an unpatched VPN and a maintenance account carried an uncomfortable message about basic patch and access hygiene. Because the access route was identified, cut off and the account suspended, the incident was assessed as contained.
Timeline
Attackers access files from the Digital Agency's Government Solution Service (GSS) using a maintenance and operations employee's account, after exploiting a VPN vulnerability.
The Digital Agency publicly discloses that personal information may have been leaked.
Follow-up reporting details that roughly 246,000 records were exposed and that the agency suspended the account and blocked external access to the affected server.
Sources
- bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/japans-digital-agency-says-vpn-flaw-exposed-246-000-personnel-records/
- securityweek.comhttps://www.securityweek.com/240000-hit-by-data-breach-at-japans-digital-agency/
- japantimes.co.jphttps://www.japantimes.co.jp/news/2026/09/11/japan/digital-agency-information-leakage/