2 Remove Virus

Japan government VPN breach may have exposed 246,000 personnel records

Japan’s Digital Agency has disclosed a security breach that may have exposed roughly 246,000 records containing personal information belonging to government workers and people connected to government operations.

 

 

The incident affected the Government Solution Service (GSS), a shared system used by Japanese government ministries and agencies. Investigators determined that an outside attacker exploited a vulnerability in VPN equipment to enter the environment and gain unauthorized access.

The first warning came on June 25, 2026, when the agency detected unusually large-scale access to files through an account belonging to a maintenance and operations worker. An investigation eventually established on July 9 that a third party had exploited the VPN vulnerability.

The agency responded by suspending the affected maintenance account and blocking communications between the compromised equipment and external networks.

An investigation conducted with outside security specialists found that files containing personal information may have been exposed. Around 189,000 of the potentially affected records relate to employees of organizations using GSS and other public officials involved in their operations.

Another 57,000 concern companies and individuals involved in work performed for those organizations.

The files contained approximately 236,000 names and 231,000 email addresses. Around 94,000 telephone numbers and 1,000 addresses were also potentially affected. These figures overlap because individual records can contain several types of information.

The Digital Agency stressed that the incident did not expose personal information belonging to the general Japanese public. My Number identification numbers, bank account information, and pension numbers were also not included in the potentially compromised files.

Many of the phone numbers and addresses involved were work contact details or government office locations rather than private residential information.

The agency has not identified the VPN product involved or publicly disclosed the specific vulnerability exploited. However, it said the security flaw was rated medium severity and was not a previously unknown zero-day vulnerability.

No misuse of the potentially exposed information has been confirmed so far. Nevertheless, the agency warned affected people to be alert for phishing emails, suspicious calls, and other attempts to impersonate government organizations using information obtained from the incident.

Individuals identified as potentially affected will be contacted directly. The breach did not disrupt government services, and the agency said it has found no confirmed unauthorized access or comparable compromise involving other systems.