Japan Digital Agency Warns VPN Breach May Have Exposed 246,000 Personnel Records
Japan’s Digital Agency says a cyberattack exploiting vulnerabilities in VPN devices used by Government Solutions Services (GSS) may have exposed around 246,000 rows of records containing personal information about civil servants and other individuals.
Attackers Exploited a VPN Vulnerability
The agency detected large-scale file access from the account of a maintenance and operations staff member and began an investigation on June 25.
In an announcement, the agency said that on July 9 it discovered that a third party had exploited a vulnerability in a network-connected VPN device to gain unauthorized access to its systems. Read the announcement.
“On the same day, we suspended the account of the maintenance and operation personnel in question and blocked communication between the compromised equipment and the outside world to prevent further unauthorized access,” the agency said.
The agency has not disclosed which VPN products were affected or which vulnerabilities were exploited. However, it said in a separate Q&A that the issue was considered medium severity and was not a zero-day vulnerability.
What Personal Information May Have Been Exposed?
The investigation found that the following information may have been compromised:
- 236,000 names
- 231,000 email addresses
- 94,000 phone numbers
- 1,000 physical addresses
Potentially affected individuals include government employees, civil servants, employees of affiliated companies, and people who use GSS systems.
The incident did not involve personal data belonging to the general public. The potentially exposed information also did not include My Number identification numbers, bank account details, or pension numbers.
Authorities Warn of Phishing and Identity Theft Risks
Authorities have not identified any cases in which the affected information was misused. However, the exposed data could increase the risk of identity theft and phishing attacks.
The Digital Agency urged people not to open links or attachments in unsolicited messages. It also reminded the public that legitimate organizations should never request passwords or credit card information by email or phone.
The agency is contacting affected individuals directly and plans to establish a dedicated support line.
Why Was the Disclosure Delayed?
The agency notified Japan’s Personal Information Protection Commission on July 15. It said the delay in publicly disclosing the incident was caused by the complexity of identifying the intrusion route, determining which information may have been affected, and confirming who may have been impacted.
The Digital Agency said the incident was limited to the affected systems. It found no evidence of unauthorized access, data leaks, or similar compromises involving other systems. The breach and the subsequent response operations also did not affect the availability of government services.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



