Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Japan’s Digital Agency says VPN flaw exposed 246,000 personnel records

Japan’s Digital Agency says a data breach may have exposed around 246,000 record rows containing personal information about government employees.

The attacker reportedly gained initial access by exploiting a vulnerability in a VPN device used by the Government Solution Service (GSS). The agency began investigating on June 25 after detecting large-scale file access from a maintenance and operations staff account.

On July 9, the agency said it discovered that a third party had used the vulnerability to gain unauthorized system access. It suspended the account, disconnected the compromised equipment from external networks, and blocked further unauthorized access.

The affected VPN product and exploited vulnerability have not been identified. Japan’s Digital Agency said the issue had a medium severity rating and was not a zero-day.

Potentially exposed individuals include government employees, public officials, and people and businesses associated with the GSS system. The breach did not expose personal data belonging to the general public, and the potentially compromised information did not include My Number identification numbers, bank-account details, or pension numbers. The agency has detected no actual misuse.

Affected individuals will be contacted directly. Japan’s Digital Agency notified the Personal Information Protection Commission on July 15 and said government services remained available.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.