509/69 Wednesday, September 16, 2026

Japan’s Digital Agency has disclosed an unauthorized access incident after attackers exploited a vulnerability in a VPN device to access the Government Solution Service (GSS), a shared IT infrastructure platform connecting 23 Japanese ministries and government agencies. The incident may have exposed approximately 246,000 records containing personal information of government officials, agency personnel, and contractors involved in government operations. The agency detected abnormal activity on June 25, 2026, confirmed on July 9 that the attack involved a VPN vulnerability, and publicly disclosed the incident on September 11.
The investigation found that the attackers exploited a vulnerability in a VPN device connected to the GSS network to gain access to the system. They then used accounts belonging to maintenance and operations staff to access and view a large number of files on the server. On July 9, the agency suspended the related accounts and cut off communication between the compromised device and external networks to prevent further access. The Digital Agency stated that the VPN vulnerability was not a zero-day and that a patch was already available at the time of the attack. The vulnerability was assessed as medium severity. However, the agency has not disclosed the VPN product name or technical details of the exploited flaw.
The potentially exposed data includes approximately 236,000 names, 231,000 email addresses, 94,000 phone numbers, and 1,000 addresses. Of the total records, around 189,000 relate to employees of agencies using GSS and government officials involved in operations, while approximately 57,000 relate to businesses and individuals serving as contractors supporting those agencies. The affected data does not include My Number identifiers, financial institution account numbers, or pension numbers. There is currently no confirmed report that the potentially exposed data has been misused. However, information such as names, email addresses, and phone numbers could be used for targeted phishing or social engineering. The Digital Agency stated that it will contact affected individuals directly and warned that it will not request passwords or payments by email or phone.
