LmCast :: Stay tuned in

Japan's Digital Agency says VPN flaw exposed 246,000 personnel records

Recorded: Sept. 14, 2026, 9:09 p.m.

Original Summarized

Japan's Digital Agency says VPN flaw exposed 246,000 personnel records

News

Featured
Latest

Hackers hijack HBO Max Reddit account to push malware in ClickFix ads

Homebrew 7.0.0 gets built-in GUI, better security controls

Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

New Android malware encrypts files, steals data, and harasses victims

Microsoft releases emergency Windows updates to fix RDS failures

Japan's Digital Agency says VPN flaw exposed 246,000 personnel records

Homebrew 7.0.0 gets built-in GUI, better security controls

Twitch extension with 30K installs exposes users’ OAuth tokens

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityJapan's Digital Agency says VPN flaw exposed 246,000 personnel records

Japan's Digital Agency says VPN flaw exposed 246,000 personnel records

By Bill Toulas

September 14, 2026
04:36 PM
0

Japan’s Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees.
The agency says that the attacker gained initial access by exploiting a vulnerability in a VPN device used by the Government Solution Service (GSS).
An investigation started on June 25, after the agency detected a large-scale file access from the account of a maintenance and operations staff member.
“On July 9th, it was discovered that a third party had used a vulnerability in a network-connected device (VPN) to gain access to the system and gain unauthorized access,” reads the announcement.
“On the same day, we suspended the account of the maintenance and operations personnel in question, cut off communication between the compromised equipment and the outside world, and prevented further unauthorized access.”
It is unclear what VPN product was affected or the vulnerability exploited in the breach. However, the Japanese agency said in a separate Q&A that the issue had a medium severity rating and was not a zero-day.
The investigation revealed that the following data may have been exposed:
236,000 names
231,000 email addresses
94,000 telephone numbers
1,000 physical addresses
Exposed individuals include government employees, public officials, and associated businesses and individuals who use the GSS system.
However, the incident did not expose personal data of the general public, and the potentially compromised information does not include My Number identification numbers, bank-account details, or pension numbers.
Also, the agency has not detected any cases of actual misuse of the impacted information, but still warned  about the elevated risk of impersonation and phishing, urging people not to open links or attachments in unsolicited communications.
The Digital Agency reminded people that it will never ask for passwords or credit card information via email or phone.
Affected individuals will be contacted directly, and the agency also set up a dedicated support line.
The agency notified Japan’s Personal Information Protection Commission on July 15, and clarified that the delay in disclosing the incident to the public was due to the complexity of determining the intrusion path, identifying potentially affected information, and establishing who was affected.
The agency says the impact was limited to the affected system, with no confirmed unauthorized access, data leakage, or comparable breaches affecting other systems. It also noted that the incident and response operations didn’t impact government services availability.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat

Related Articles:
Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentSouth Korea discloses data breach impacting diplomats worldwideArtifactory flaws chained in attacks deploying backdoor malwareCisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacksMagento StyleSmuggler zero-day exploited to deploy Linux backdoor

Actively Exploited
Data Breach
Government
Japan
N-day
VPN
Vulnerability

Bill Toulas
Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks.

Previous Article
Next Article

Post a Comment Community Rules

You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

Passkey-themed phishing attacks lead to Microsoft 365 data theft

Hackers abused Claude to extract secrets from 1.8M Android apps

Florida confirms DMV database breached via stolen police account

Sponsor Posts

EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain

Overdue a password health-check? Audit your Active Directory for free

Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. 

Patch automation needs more than speed. Action1 brings control into every stage of deployment.

Stay one step ahead of new threats in the new year. Join Huntress for the monthly Tradecraft Tuesday.

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

Japan's Digital Agency reported the discovery of a data breach stemming from a vulnerability exploited in a Virtual Private Network device utilized by the Government Solution Service (GSS), which may have exposed personal information belonging to approximately 246,000 government employees. The investigation commenced on June 25th after the agency detected large-scale file access originating from the account of a maintenance and operations staff member. The breach was discovered on July 9th, when it was ascertained that a third party had leveraged this network-connected device vulnerability to gain unauthorized access to the system. In response, the agency immediately suspended the compromised personnel account, severed communication channels from the external network for the affected equipment, and implemented measures to prevent further unauthorized access. Although the specific VPN product or the exact vulnerability exploited was not disclosed, the Japanese agency classified the incident as having a medium severity rating and noted that it was not a zero-day exploit.

The investigation revealed the extent of the potentially exposed data, which included 236,000 names, 231,000 email addresses, 94,000 telephone numbers, and 1,000 physical addresses. The individuals affected encompass government employees, public officials, and associated businesses and private individuals utilizing the GSS system. Importantly, the leaked information did not include highly sensitive data such as My Number identification numbers, bank account details, or pension numbers. Despite this, the agency issued a warning regarding the elevated risk of impersonation and phishing, advising the public against interacting with unsolicited communications, and assured that the agency would not solicit passwords or credit card information via email or phone. Affected individuals are slated to be contacted directly, and a dedicated support line has been established by the agency.

The Digital Agency notified Japan’s Personal Information Protection Commission on July 15th, explaining that the delay in public disclosure resulted from the complexity involved in determining the precise intrusion path, identifying all potentially affected data sets, and establishing the scope of the breach accurately. The agency further confirmed that the impact was strictly limited to the affected system, and no confirmed unauthorized access, data leakage, or comparable breaches were detected in other systems. Furthermore, the incident response and mitigation efforts did not negatively affect the availability of essential government services. Bill Toulas reported on this incident, highlighting the systemic response to the security failure.