Japan's Digital Agency has disclosed a data breach affecting approximately 246,000 rows of personnel records belonging to government employees, public officials, and associated businesses, after an attacker exploited a vulnerability in a VPN device connected to the Government Solution Service.
The breach, first reported by BleepingComputer, came to light on June 25 when the agency detected a large-scale file access originating from the account of a maintenance and operations staff member.
"On July 9th, it was discovered that a third party had used a vulnerability in a network-connected device (VPN) to gain access to the system and gain unauthorized access," the agency said in its public announcement. On the same day, it suspended the compromised account and severed external communication links to prevent further intrusion.
The categories of potentially exposed data include 236,000 names, 231,000 email addresses, 94,000 telephone numbers, and approximately 1,000 physical addresses. The agency confirmed that the breach did not expose My Number identification numbers, bank-account details, pension numbers, or any personal data belonging to the general public.
The specific VPN product involved and the exact vulnerability exploited have not been publicly identified. In a separate Q&A, the agency said the flaw carried a medium severity rating and was not a zero-day, underscoring that a known, patchable vulnerability was the entry point for the intrusion.
The agency notified Japan's Personal Information Protection Commission on July 15. It attributed the delay in public disclosure to the complexity of tracing the intrusion path, determining which records were potentially accessible, and identifying the full scope of affected individuals.
As of the disclosure date, the agency said it had found no confirmed cases of data misuse. It nonetheless warned affected individuals of an elevated risk of impersonation and phishing attacks, advising against opening unsolicited links or attachments and noting that the agency will never request passwords or credit card information by email or phone. Affected individuals are to be contacted directly, and a dedicated support line has been established.
The agency also said the breach was contained to the affected system, with no confirmed unauthorized access or data leakage detected across other government platforms, and that service availability was not disrupted at any point during the incident or the subsequent response.
The disclosure comes amid a broader wave of government-sector intrusions exploiting enterprise networking equipment. The incident reinforces longstanding concerns among security researchers about the exposure created by unpatched VPN appliances in critical infrastructure environments — a vector that threat actors, including state-sponsored groups, have consistently targeted in recent years. How Japan's Digital Agency will update its device patching and access-monitoring procedures in the aftermath of this breach is likely to draw scrutiny from both domestic regulators and international partners.