240,000 Hit by Data Breach at Japan’s Digital Agency
Hackers exploited a vulnerability in a VPN product to steal the personal information of roughly 240,000 people.

Hackers exploited a vulnerability in a VPN product to steal the personal information of roughly 240,000 people.
Japan’s Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees. Also, the agency has not detected any cases of actual misuse of the impacted information, but still warned about the elevated risk of impersonation and phishing, urging people not to open links or attachments in unsolicited communications.
The agency says that the attacker gained initial access by exploiting a vulnerability in a VPN device used by the Government Solution Service (GSS). An investigation started on June 25, after the agency detected a large-scale file access from the account of a maintenance and operations staff member. “On July 9th, it was discovered that a third party had used a vulnerability in a network-connected device (VPN) to gain access to the system and gain unauthorized access,” reads the announcement . The investigation revealed that the following data may have been exposed: Exposed individuals include government employees, public officials, and associated businesses and individuals who use the GSS system.
What changed
“On the same day, we suspended the account of the maintenance and operations personnel in question, cut off communication between the compromised equipment and the outside world, and prevented further unauthorized access.” It is unclear what VPN product was affected or the vulnerability exploited in the breach.
Who is affected
The agency says that the attacker gained initial access by exploiting a vulnerability in a VPN device used by the Government Solution Service (GSS).
An investigation started on June 25, after the agency detected a large-scale file access from the account of a maintenance and operations staff member.
“On July 9th, it was discovered that a third party had used a vulnerability in a network-connected device (VPN) to gain access to the system and gain unauthorized access,” reads the announcement .
The investigation revealed that the following data may have been exposed: Exposed individuals include government employees, public officials, and associated businesses and individuals who use the GSS system.
However, the incident did not expose personal data of the general public, and the potentially compromised information does not include My Number identification numbers, bank-account details, or pension numbers.
The agency says the impact was limited to the affected system, with no confirmed unauthorized access, data leakage, or comparable breaches affecting other systems.
Why this matters
Japan’s Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees.
Also, the agency has not detected any cases of actual misuse of the impacted information, but still warned about the elevated risk of impersonation and phishing, urging people not to open links or attachments in unsolicited communications.
What to watch next
Watch for additional exploitation reporting, newly published indicators, and changes to vendor guidance.