Japan’s Digital Agency breach exposes data of 240,000
Hackers used a maintenance employee’s account to access the Government Solution Service, exposing names, emails, workplace addresses and phone numbers for about 240,000 people.
Japan’s Digital Agency disclosed a data breach after detecting unauthorized access to its Government Solution Service in late June. An investigation completed in July found attackers used a maintenance and operations employee’s account to retrieve files and traced the intrusion to exploitation of a vulnerability in a VPN product.
Investigators determined more than 246,000 records were compromised: about 236,000 names, roughly 231,000 email addresses, around 94,000 phone numbers and about 1,000 addresses.
The affected records belong to users of the Government Solution Service as well as public officials, administrative staff and businesses and individuals who work with the service. The agency noted most addresses and phone numbers were linked to workplaces, such as government buildings or offices, and were provided when applying to use GSS.
Other types of personal data were not affected. Individual identification numbers and financial account information were not among the compromised records, and no information belonging to the general public outside GSS users was exposed.
After confirming the exploitation, the agency blocked external access to the affected server and suspended the employee account used in the attack. The agency declined to name the VPN product and noted the exploited vulnerability had been publicly disclosed before the attack. Officials plan to strengthen vulnerability management processes.
The agency reported no other systems were compromised and published an FAQ explaining which categories of people were affected and that the leaked contact details were largely occupational rather than personal home addresses.







