Japan’s Digital Agency says attackers may have exposed around 246,000 rows of personnel data after exploiting a vulnerability in a government VPN device. The affected information includes names, email addresses, telephone numbers and physical addresses.
The agency has found no evidence that criminals misused the exposed data. However, it warned affected individuals about an increased risk of phishing and impersonation attempts.
VPN Flaw Gives Attacker Initial Access
The Japan VPN breach affected a device connected to the Government Solution Service. The GSS provides a common working environment for central government organisations.
The Digital Agency began investigating on June 25. It had detected large-scale file access involving the account of a maintenance and operations employee.
Investigators later determined that an external attacker had exploited a vulnerability in a VPN device. The weakness allowed the intruder to enter the system and access files without authorisation.
The agency confirmed the intrusion path on July 9. On the same day, it suspended the compromised employee account.
Officials also disconnected communication between the affected equipment and external networks. These actions prevented the attacker from gaining further access.
Vulnerability Was Not a Zero-Day
The Digital Agency has not identified the affected VPN product publicly. It has also withheld specific details about the exploited vulnerability.
However, officials said the flaw carried a medium severity rating. The vulnerability was already known when the attack occurred and was not a zero-day.
A zero-day vulnerability has no available fix or was previously unknown to the product’s developer. In this case, the available information suggests that a disclosed weakness remained exploitable on the government device.
The agency has not explained why the affected equipment remained vulnerable. It also did not reveal when the hackers first entered the system.
Breach Exposes Government Personnel Data
The investigation found that approximately 246,000 database rows may have become accessible during the intrusion.
The exposed records contained around 236,000 names and 231,000 email addresses. In addition, they included approximately 94,000 telephone numbers and 1,000 physical addresses.
The information relates to government employees and public officials. It also covers associated individuals and businesses that use the GSS environment.
However, the breach did not expose personal information belonging to the general public.
The compromised records also excluded several highly sensitive categories. According to the agency, the data did not include My Number identification numbers, bank account details or pension numbers.
The different totals indicate that individual records did not always contain every type of personal information.
Officials Warn About Phishing Attempts
Investigators have not detected confirmed misuse of the exposed information. Nevertheless, the available contact details could support convincing phishing attacks.
Criminals may use names, government roles, email addresses and telephone numbers to impersonate colleagues or trusted organisations. They could then attempt to collect login credentials or distribute malware.
Therefore, the Digital Agency urged affected people to remain cautious when receiving unsolicited messages. Recipients should avoid opening unexpected links or attachments.
The agency also reminded individuals that it will never request passwords or credit card details through email or telephone calls.
Officials plan to contact affected individuals directly. Additionally, the government has established a dedicated support line for people seeking more information.
Agency Reports Incident to Regulator
The Digital Agency notified Japan’s Personal Information Protection Commission about the incident on July 15.
However, officials did not immediately announce the breach publicly. The agency said it needed time to investigate the intrusion path and determine which information the attacker could have accessed.
Investigators also had to identify the people and organisations potentially affected by the incident. These factors delayed the public disclosure.
The Digital Agency says it contained the breach within the compromised system. It has found no confirmed unauthorised access or similar incidents affecting other government environments.
Furthermore, the response did not interrupt the availability of government services. Officials said public systems continued operating normally throughout the investigation and containment process.
The agency has not disclosed who carried out the attack or whether the intruder successfully removed the accessible records.


0 responses to “Japan VPN Breach Exposes 246,000 Personnel Records”