A major cybersecurity incident has come to light in Japan, where a vulnerability in a Virtual Private Network (VPN) device used by government employees may have exposed sensitive personal information of over 246,000 individuals. The breach was discovered by Japan’s Digital Agency, which provides digital services to the government, and affects personnel records, including names, email addresses, telephone numbers, and physical addresses.
The incident occurred when an attacker exploited a vulnerability in the VPN device used by the Government Solution Service (GSS), allowing them to gain unauthorized access to the system. The agency detected the breach on June 25, after noticing a large-scale file access from a maintenance staff member’s account. However, it wasn’t until July 9 that they were able to pinpoint the vulnerability and prevent further unauthorized access.
The affected individuals include government employees, public officials, and associated businesses and individuals who use the GSS system. While the breach did not expose sensitive personal data such as My Number identification numbers, bank-account details, or pension numbers, there is still a risk of impersonation and phishing attacks. The agency has warned that people should be cautious when receiving unsolicited communications, especially those that ask for passwords or credit card information.
It’s worth noting that the VPN product affected by the breach has not been disclosed, nor has the specific vulnerability exploited by the attacker. However, the Japanese agency has confirmed that the issue had a medium severity rating and was not a zero-day exploit. A zero-day exploit refers to an attack that takes advantage of a previously unknown vulnerability in software or hardware.
The investigation into the breach revealed that approximately 236,000 names, 231,000 email addresses, 94,000 telephone numbers, and 1,000 physical addresses may have been exposed. While the agency has not detected any cases of actual misuse of the impacted information, they are urging people to remain vigilant and take precautions against potential attacks.
In response to the breach, the Digital Agency has set up a dedicated support line for affected individuals and will be contacting them directly to inform them of the incident. The agency has also notified Japan’s Personal Information Protection Commission and clarified that the delay in disclosing the incident to the public was due to the complexity of determining the intrusion path, identifying potentially affected information, and establishing who was affected.
The incident serves as a reminder for individuals and organizations alike to prioritize cybersecurity measures, especially when using VPNs or other network-connected devices. A strong password policy, regular software updates, and employee education on phishing attacks can go a long way in preventing similar incidents from occurring. Affected individuals should remain vigilant and take steps to protect themselves against potential attacks, such as being cautious with unsolicited communications and verifying the authenticity of emails or phone calls before responding.
Source: Bleeping Computer — 2026-09-14