Japan’s Digital Agency has disclosed a data breach that may have exposed personal information from around 246,000 records after attackers exploited a vulnerability in a VPN device connected to a government system.

The incident involved the Government Solution Service (GSS), which supports government-related systems. The agency began investigating on June 25 after detecting unusually large-scale file access from an account belonging to a maintenance and operations staff member.

Investigators later found that an outside party had used a vulnerability in a network-connected VPN device to gain unauthorized access. After discovering the intrusion, the agency suspended the affected account, disconnected the compromised equipment from the outside network, and took steps to block further unauthorized access.

Japan’s Digital Agency has not identified the VPN product involved or disclosed the specific vulnerability that was exploited. However, it said the flaw was rated as medium severity and was not a zero-day vulnerability.

The investigation found that the potentially exposed information includes approximately 236,000 names, 231,000 email addresses, 94,000 telephone numbers, and 1,000 physical addresses. The affected people include government employees, public officials, businesses, and other individuals using the GSS system.

Despite the size of the incident, the agency said personal information belonging to the general public was not affected. The compromised information also did not include My Number identification numbers, bank account details, or pension numbers.

There is currently no evidence that the exposed information has been misused. However, the Digital Agency warned that the incident could increase the risk of impersonation and phishing attacks. People potentially affected by the breach have been advised not to open suspicious links or attachments in unsolicited messages.

READ
cPanel Fixes Critical Flaw That Could Give Attackers Root Access

The agency also reminded people that it will never ask for passwords or credit card information through email or phone calls. Individuals affected by the incident will be contacted directly, while a dedicated support line has also been established.

The Digital Agency notified Japan’s Personal Information Protection Commission about the incident on July 15. It explained that the public disclosure took time because investigators needed to determine how the intrusion occurred, identify the potentially exposed information, and establish who may have been affected.


Buy ExpressVPN with PayPal or Credit Card

The agency said the impact was limited to the affected system, with no confirmed unauthorized access or data leakage involving other systems. The incident also did not affect the availability of government services.

Advertisement