Japan Government Network Breach May Expose Data of 246,000 People
Japan’s Digital Agency has disclosed a breach of its shared government network that may have exposed personal information belonging to about 246,000 people across organizations using the Government Solution Service (GSS). The potentially affected records include names, email addresses, telephone numbers and physical addresses. Personal information belonging to the general public was not involved.
The agency detected unusual access to a large number of files on June 25 through an account used by a maintenance and operations worker. An investigation later established that an outside party had exploited a vulnerability in a VPN-connected network device to gain access to the system. The affected account was suspended and external communications from the compromised equipment were cut off on July 9.
What Information May Have Been Exposed
The potentially affected data covers roughly 236,000 names, 231,000 email addresses, 94,000 telephone numbers and about 1,000 physical addresses. The records involve employees and officials of government organizations using GSS, as well as businesses and individuals involved in their work.
The Digital Agency said the affected information does not include Japan’s My Number identification numbers, bank account information or pension numbers. About 189,000 records relate to government employees, officials and others connected to GSS-using organizations, while around 57,000 concern businesses and individuals working with those organizations.
VPN Vulnerability Used in the Attack
The intrusion involved a vulnerability in VPN equipment used to connect to the government service. The agency’s investigation found that the attackers were able to use the weakness to enter the system and access files through the maintenance account.
The agency has not publicly identified the affected VPN product or vulnerability. The investigation into the incident is still ongoing, and officials have said some technical details cannot be disclosed for security reasons.
No Confirmed Misuse So Far
Japan’s Digital Agency said it has not confirmed any secondary misuse of the potentially exposed information. It plans to identify affected individuals and organizations and contact them directly.
Officials have warned that names, email addresses and phone numbers could be used in impersonation attempts, phishing messages or fraudulent calls. People potentially affected have been advised to be cautious about communications claiming to come from the Digital Agency or other government organizations.
The incident puts additional attention on the security of shared government infrastructure, where a compromise of one system can potentially expose information connected to multiple public-sector organizations. The Digital Agency says it is reviewing its vulnerability-management practices and external connection methods as part of its measures to prevent a recurrence.
