Pierluigi Paganini
September 15, 2026

Japan ‘s Digital Agency disclosed that attackers exploited a vulnerability in a VPN device to access its Government Solution Service (GSS), potentially leaking personal information belonging to approximately 246,000 government employees, public officials, and contractors. The breach was detected on June 25 and confirmed as a VPN exploitation on July 9, meaning the public disclosure came 78 days after the initial detection and 63 days after the intrusion method was identified.
“It has come to our attention that, due to unauthorized external access, some files containing personal information handled on the Government Solution Service (GSS), operated by the Digital Agency, may have been leaked to an external party.” reads the advisory. “We have confirmed that the personal information that may have been leaked pertains to employees of various ministries and agencies that use GSS (hereinafter referred to as “GSS user organizations”) and those involved in their work, and does not include personal information of the general public.”
GSS connects 23 Japanese ministries and agencies through shared IT infrastructure. A breach of this platform could potentially affect many government organizations at once.
The attack followed a straightforward path. An outsider exploited a vulnerability in a VPN device that serves the GSS network, accessed the system using a maintenance and operations staff member’s account, and browsed a large number of files on the server. The agency detected the unusual activity on June 25, confirmed the VPN exploitation on July 9, then suspended the maintenance account and cut off external communications from the compromised hardware the same day. A subsequent investigation with external security specialists confirmed that files containing personal information may have been exfiltrated.
“On June 25, 2026, we detected that a large number of files on the server had been accessed using the account of a maintenance and operations staff member, and we began an investigation. On July 9, it was discovered that a third party had exploited a vulnerability in the network connection device (VPN) to infiltrate the system and gain unauthorized access. On the same day, we suspended the maintenance and operations staff member’s account and cut off communication between the compromised equipment and the outside world to prevent further unauthorized access.” continues the report.”As a result of our investigation with the cooperation of an external expert company, we have confirmed that there is a possibility that personal information may have been leaked to an external party.”

The potentially exposed data breaks down to roughly 236,000 names, 231,000 email addresses, 94,000 phone numbers, and approximately 1,000 physical addresses. Of the 246,000 total records, about 189,000 belong to employees of GSS-using organizations and public officials involved in their work, including staff at independent administrative agencies. The remaining 57,000 records relate to businesses and individuals contracted to support those organizations. The data doesn’t include My Number identification numbers, financial institution account numbers, or pension numbers.
The VPN flaw was rated medium severity and wasn’t a zero-day. A patch was already available when attackers exploited it, but the agency hasn’t revealed the VPN product or the flaw.
Japan’s privacy regulator was notified on July 15, six days after the attack was confirmed. The Digital Agency said the delay came from the difficulty of tracing the attack, assessing the affected data, and identifying those involved.
The incident also shows the risk of leaving a known, patchable flaw unaddressed on infrastructure shared by 23 ministries.
No confirmed misuse of the exposed data has been reported. However, the leaked names, email addresses and phone numbers could enable targeted phishing and social engineering, including scams impersonating Japan’s Digital Agency. The agency will contact affected people directly and warns that it will never request passwords or payments by email or phone.
The breach is one in a series of significant cybersecurity incidents affecting Japanese institutions. NISC, Japan’s National Cyber Incident Readiness and Strategy Center, disclosed a breach in 2023 that affected its email system. Japan Aerospace Exploration Agency (JAXA) reported unauthorized access to its systems in 2024. The pattern points to systemic challenges in patching and access management across Japan’s public sector infrastructure rather than isolated failures.
The Digital Agency’s planned remediation includes improved vulnerability management and changes to external connection methods, which are the right responses to the immediate incident. Whether they address the underlying governance question is harder to assess from the public advisory alone.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)