started · updated
Japan Digital Agency reports breach of 246,000 records
Japan’s Digital Agency has confirmed a data breach involving the Government Solution Service (GSS), a shared platform used across various ministries and agencies. The agency reported that unauthorized access may have exposed approximately 246,000 personal records.
The intrusion was facilitated by a vulnerability in a VPN device. Attackers reportedly exploited this flaw and subsequently used a maintenance operations account to access files at scale. The agency detected suspicious activity on June 25 and confirmed the breach on July 9, at which point it disabled the compromised account and severed external connections.
The potentially exposed information includes names, email addresses, and phone numbers belonging to public officials, government employees, and contractors. The agency clarified that the breach does not affect the general public and confirmed that sensitive data, such as My Number identifiers, bank details, and pension numbers, were not compromised.
Entities
Digital Agency · Government Solution Service · Japan Digital Agency · Personal Information Protection Commission
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 2 SOURCES] Attackers used a maintenance operations account to access files at scale. www.asiapacificsecuritymagazine.com · www.technadu.com
- [○ 1 SOURCE] The VPN vulnerability was classified as medium severity and was not a zero-day exploit. www.technadu.com
- [○ 1 SOURCE] My Number identifiers, bank details, and pension numbers were not exposed. www.asiapacificsecuritymagazine.com
- [● 2 SOURCES] The exposed data includes names, email addresses, and phone numbers of public officials and contractors. www.asiapacificsecuritymagazine.com · www.technadu.com
- [● 2 SOURCES] Suspicious activity was detected on June 25, and the cause was confirmed on July 9. www.asiapacificsecuritymagazine.com · www.technadu.com
- [● 2 SOURCES] Approximately 246,000 personal records may have been exposed due to unauthorized access. www.asiapacificsecuritymagazine.com · www.technadu.com
- [● 2 SOURCES] The breach occurred via a vulnerability in a VPN device used by the Government Solution Service (GSS). www.asiapacificsecuritymagazine.com · www.technadu.com
- [○ 1 SOURCE] The agency reported the incident to the Personal Information Protection Commission on July 15. www.technadu.com