Japan's Digital Agency says a VPN flaw leaked 246,000 staff records
A patchable bug in a remote-access box gave an attacker the keys to a government support system for weeks before anyone noticed.

Key points
- Japan's Digital Agency disclosed that around 246,000 records tied to government employees and contractors may have been exposed.
- The attacker got in by exploiting a vulnerability in a VPN device, remote-access equipment that lets staff log in from outside the office, used by the Government Solution Service (GSS).
- Staff spotted unusual file access on 25 June; the intrusion path was confirmed on 9 July; Japan's Personal Information Protection Commission was notified on 15 July.
- Exposed fields include 236,000 names, 231,000 email addresses, 94,000 phone numbers and 1,000 physical addresses.
- My Number identifiers, bank details and pension numbers were not in the affected data, and no misuse has been observed.
Japan's Digital Agency has told the public that an intruder walked into one of its internal systems through a known flaw in a VPN appliance and had access to roughly 246,000 rows of personal data belonging to government workers and the contractors who deal with them.
The agency runs the Government Solution Service, the shared back-office platform civil servants and their suppliers use for day-to-day admin. That's the system the attacker reached. First reported by BleepingComputer, the breach surfaced when staff noticed a maintenance account pulling files at a scale that didn't match the job.
How did the attackers get in?
Through the VPN. A third party exploited a vulnerability in a network-connected VPN device to gain access, then used a maintenance and operations account to rummage around inside the GSS environment.
No vendor name or CVE, the industry's tracking number for a known software flaw, has been released. The agency said the bug carried a medium severity rating and was not a zero-day, meaning a fix already existed when the attack happened. Someone had not patched a box that was sitting on the public internet.
That's the boring, recurring failure mode. Edge devices like VPN concentrators and remote-access gateways are the front door, and they're the first thing attackers scan after a vendor advisory drops. We covered a structurally similar government records exposure when ShinyHunters abused a password-reset flaw in Florida's law-enforcement lookup tool on 8 September.
What was exposed?
Mostly contact details for people who work with the government, not the general public. The agency published a breakdown of the potentially affected fields.
| Data type | Records |
|---|---|
| Names | 236,000 |
| Email addresses | 231,000 |
| Phone numbers | 94,000 |
| Physical addresses | 1,000 |
Affected people include government employees, public officials, and associated businesses that use GSS. My Number identifiers (Japan's national ID), bank account details and pension numbers are not in the exposed set. No misuse has been detected.
Should the people in the data worry?
A little, in the ordinary sense. Names, work emails and phone numbers are exactly the ingredients for a convincing phishing email, the sort of fake message designed to trick someone into handing over a password or clicking a booby-trapped link.
The Digital Agency is contacting affected people directly and has opened a dedicated support line. It also reminded recipients that it'll never ask for a password or credit card number by email or phone. If a message claiming to be from the agency asks for either, it isn't real.
The timeline the postmortem will lean on
Staff spotted the abnormal file access on 25 June. The intrusion path was confirmed on 9 July, at which point the account was suspended and the compromised device was cut off from the outside world. Regulators were told on 15 July. Public disclosure came later, which the agency attributes to the complexity of determining who was affected and how the attacker got in.
Roughly two weeks between detection and public containment description isn't unusual for a government body, but it's a long window for anyone downstream of the data. The government services themselves stayed online throughout.
An unpatched VPN appliance is a breach with a date on it, not an if.



