Skip to content

Security2 publishers2 min readPublished

Patchable VPN flaw exposed 246,000 personnel records on Japan's shared government platform

Japan's Digital Agency says an intruder used a medium-severity VPN bug that already had a patch, then worked through a maintenance account on a file platform shared by 23 ministries. Disclosure came 78 days after detection.

The Watch · Security desk

Photograph accompanying Patchable VPN flaw exposed 246,000 personnel records on Japan's shared government platform
Photo: securityaffairs.com

What happened

  • Japan's Digital Agency detected a large volume of file access from the account of a maintenance and operations staff member on June 25, 2026, and opened an investigation.
  • On July 9 it established that a third party had exploited a vulnerability in a VPN device to get in, then suspended that account and cut the compromised equipment's external communications.
  • The exploited flaw was rated medium severity, was not a zero-day, and already had a patch available when the attacker used it.
  • The potentially exposed data covers roughly 236,000 names, 231,000 email addresses, 94,000 telephone numbers and about 1,000 physical addresses.
  • About 189,000 of the records cover staff and officials at the ministries and agencies that use GSS, and 57,000 cover contracted businesses and individuals working for them.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure 94 percent of the exposed rows carry an email address. The people reachable through them work across the 23 tenant organisations, while the breached device was the Digital Agency's to patch.
  • constraint The agency did not name the product or the vulnerability, so security teams at the tenant ministries cannot tell whether the same unpatched appliance is sitting on their own perimeter now.
  • contradiction Security Affairs says the shared platform is a route for one breach to hit many organisations at once, while the agency reports containment to the single system, so what the 23 tenants share is the data pool.
  • precedent A 78-day gap between detection and public notice sets the working expectation for the next shared-service breach, and staff at tenant ministries learn of their own exposure on the operator's schedule.

The entry point was a VPN device serving the Government Solution Service, and the pivot was a maintenance and operations account [2]. The agency did not identify the product or the vulnerability, so a tenant ministry running the same appliance at its own edge cannot check itself against this incident [6].

BleepingComputer describes 246,000 record rows containing personal information [20]; Security Affairs describes records belonging to approximately 246,000 employees, officials and contractors [1]. With 236,000 names in 246,000 rows, the number of distinct people is unresolved [8]. The proportions are firmer: 231,000 email addresses is 94 percent of the rows, and 94,000 telephone numbers is 38 percent [1][2].

Japan's Personal Information Protection Commission was told on July 15, six days after the intrusion path was confirmed [11]. The public was told about 58 days after the regulator [4]. Security Affairs puts the public disclosure at 78 days after detection and 63 days after the method was identified [13]; those two intervals sit a day apart, because June 25 to July 9 is 14 days and 78 minus 63 is 15 [5]. The agency said the delay came from the complexity of determining the intrusion path, identifying the potentially affected information, and establishing who was affected [12].

The leaked information "pertains to employees of various ministries and agencies that use GSS ... and does not include personal information of the general public," the advisory reads [19]. The set also excludes My Number identification numbers, bank-account details and pension numbers [10].

GSS connects 23 Japanese ministries and agencies through shared IT infrastructure [7], and Security Affairs argues that a breach of the platform could affect many government organisations at once [17]. The agency says the impact was limited to the affected system, with no confirmed unauthorized access, data leakage or comparable breaches on other systems, and no effect on the availability of government services [16].

Security Affairs sets the breach alongside two earlier Japanese cases: NISC disclosed a 2023 breach of its email system, and JAXA reported unauthorized access to its systems in 2024 [18]. No actual misuse of the GSS data has been detected [14]. The warning the agency issued is about impersonation, including scams posing as the Digital Agency, and it says it will never ask for passwords or credit card information by email or phone [15].

What to watch

  • Whether the Digital Agency identifies the VPN product and the flaw.
  • Any reported phishing or fraud that impersonates the Digital Agency using the exposed names, email addresses and phone numbers.
  • Whether the Personal Information Protection Commission takes issue with the 78-day gap between detection and public notice.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories