Cybersecurity

VPN Vulnerability May Have Exposed Data From 246,000 Records of Government Employees in Japan

Japan’s Digital Agency said that an attacker exploited a medium-severity vulnerability in a VPN device connected to the Government Solution Service, which may have enabled access to approximately 246,000 rows of records belonging to employees and associated organizations. The data did not include My Number numbers, bank accounts, or pension numbers, and no confirmed cases of misuse have been identified so far.

2026-09-14
3 min read
6 views
فريق تحرير certi.news
VPN Vulnerability May Have Exposed Data From 246,000 Records of Government Employees in Japan

Japan’s Digital Agency announced the discovery of a breach that may have exposed approximately 246,000 rows of records containing personal information about government employees, officials, organizations, and individuals who use the Government Solution Service (GSS). According to the agency, the attacker began accessing the system by exploiting a vulnerability in a VPN device connected to the network and used by the government system.

The investigation began on June 25 after extensive access to files was detected using an account belonging to an employee responsible for maintenance and operations. On July 9, the agency concluded that a third party had exploited a vulnerability in a network-connected device to gain unauthorized access to the system. It immediately suspended the relevant employee’s account, isolated the affected device from external communications, and took measures to prevent continued unauthorized access.

What data may have been accessed?

  • 236,000 names.
  • 231,000 email addresses.
  • 94,000 telephone numbers.
  • 1,000 physical addresses.

The agency did not identify the affected VPN product or the number of the exploited vulnerability. However, it clarified in separate questions and answers that the vulnerability was classified as medium severity and was not a zero-day vulnerability—that is, it was not unknown to the developer or lacking a fix when it was exploited, according to the usual meaning of the term.

What was not affected?

The agency said that data on the general population was not within the scope of the incident, and that the potentially compromised information did not include national identification numbers known as My Number, bank account details, or pension numbers. The agency has not identified any confirmed cases of information misuse so far, but it warned of increased risks of identity theft and phishing.

The agency asked affected individuals not to open links or attachments in unexpected communications and reminded them that its employees would not request passwords or credit card information by email or telephone. It said that affected people would be notified directly and that a dedicated support line would be provided.

Why does this news matter?

The incident shows that compromising a VPN device does not necessarily require targeting a public database to have a broad impact; a single maintenance account and extensive access logs were enough to initiate an investigation into a system containing contact data for government organizations and associated parties. The fact that the vulnerability was not a zero-day also does not eliminate its impact, as managing network-connected devices, monitoring privileged accounts, and isolating affected systems remain critical elements in limiting the spread.

The agency reported the incident to Japan’s Personal Information Protection Commission on July 15. It attributed the delay in the public announcement to the complexity of determining the breach path, the data potentially affected, and the people involved. It confirmed that the impact was limited to the affected system, that no unauthorized access or similar leak had been established in other systems, and that the availability of government services was not affected by the incident and response operations.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news