VPN Vulnerability Exposes 246,000 Japanese Government Personnel Records
Japan's **Digital Agency** has disclosed a significant data breach, potentially exposing the personal information of approximately 246,000 government employees and associated individuals. The breach was initiated through a vulnerability in a VPN device used by the **Government Solution Service (GSS)**, leading to unauthorized access to sensitive records.

Japan's **Digital Agency** has revealed a data breach impacting around 246,000 rows of personal information belonging to government employees and affiliated entities. The agency confirmed that attackers exploited a vulnerability in a VPN device utilized by the **Government Solution Service (GSS)** to gain initial access.
### Breach Detection and Response
The incident came to light on June 25, following the detection of large-scale file access originating from a maintenance and operations staff member's account. Subsequent investigation confirmed that a third party had leveraged a VPN vulnerability to infiltrate the system and gain unauthorized access by July 9.
Upon discovery, the agency promptly suspended the compromised account, severed external communication with the affected equipment, and implemented measures to prevent further unauthorized access.
### Vulnerability Details Remain Undisclosed
The specific VPN product and the exploited vulnerability have not been publicly identified. However, the **Digital Agency** clarified in a separate Q&A that the vulnerability was rated as medium severity and was not a zero-day exploit.
### Exposed Data Points
The comprehensive investigation identified the following data points as potentially exposed:
* 236,000 names
* 231,000 email addresses
* 94,000 telephone numbers
* 1,000 physical addresses
The compromised individuals include government employees, public officials, and associated businesses and individuals who interact with the **GSS** system. Importantly, the breach did not affect the general public, nor did it expose sensitive identifiers such as **My Number** identification numbers, bank account details, or pension numbers.
### Mitigating Risks and Public Advisories
While no instances of actual misuse of the exposed data have been detected, the agency has issued a warning about the heightened risk of impersonation and phishing attempts. Affected individuals are urged to exercise caution and avoid opening unsolicited links or attachments.
The **Digital Agency** emphasized that it will never request passwords or credit card information via email or phone. Direct contact will be made with affected individuals, and a dedicated support line has been established to assist them.
### Transparency and Incident Timeline
The agency formally notified Japanβs **Personal Information Protection Commission** on July 15. The delay in public disclosure was attributed to the intricate process of identifying the intrusion path, pinpointing affected information, and determining the scope of impacted individuals.
Authorities have confirmed that the impact was isolated to the compromised system, with no evidence of unauthorized access, data leakage, or similar breaches affecting other government systems. Furthermore, the incident and subsequent response operations did not disrupt the availability of government services.