CYBER DELTA FORCESearch
Data BreachesDEVELOPING

240,000 Hit by Data Breach at Japan’s Digital Agency

Hackers exploited a vulnerability in a VPN product to steal the personal information of roughly 240,000 people.

CDF News DeskSecurityWeek15 Sept 2026, 5:15 pm
Image courtesy of SecurityWeek. Original report
CDF REPORT

Hackers exploited a vulnerability in a VPN product to steal the personal information of roughly 240,000 people.

Japan’s Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees. Also, the agency has not detected any cases of actual misuse of the impacted information, but still warned about the elevated risk of impersonation and phishing, urging people not to open links or attachments in unsolicited communications.

The agency says that the attacker gained initial access by exploiting a vulnerability in a VPN device used by the Government Solution Service (GSS). An investigation started on June 25, after the agency detected a large-scale file access from the account of a maintenance and operations staff member. “On July 9th, it was discovered that a third party had used a vulnerability in a network-connected device (VPN) to gain access to the system and gain unauthorized access,” reads the announcement . The investigation revealed that the following data may have been exposed: Exposed individuals include government employees, public officials, and associated businesses and individuals who use the GSS system.

What changed

“On the same day, we suspended the account of the maintenance and operations personnel in question, cut off communication between the compromised equipment and the outside world, and prevented further unauthorized access.” It is unclear what VPN product was affected or the vulnerability exploited in the breach.

Who is affected

The agency says that the attacker gained initial access by exploiting a vulnerability in a VPN device used by the Government Solution Service (GSS).

An investigation started on June 25, after the agency detected a large-scale file access from the account of a maintenance and operations staff member.

“On July 9th, it was discovered that a third party had used a vulnerability in a network-connected device (VPN) to gain access to the system and gain unauthorized access,” reads the announcement .

The investigation revealed that the following data may have been exposed: Exposed individuals include government employees, public officials, and associated businesses and individuals who use the GSS system.

However, the incident did not expose personal data of the general public, and the potentially compromised information does not include My Number identification numbers, bank-account details, or pension numbers.

The agency says the impact was limited to the affected system, with no confirmed unauthorized access, data leakage, or comparable breaches affecting other systems.

Why this matters

Japan’s Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees.

Also, the agency has not detected any cases of actual misuse of the impacted information, but still warned about the elevated risk of impersonation and phishing, urging people not to open links or attachments in unsolicited communications.

What to watch next

Watch for additional exploitation reporting, newly published indicators, and changes to vendor guidance.

MORE IN DATA BREACHES

More cybersecurity reporting

Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML ExportsThe Hacker News · 14 Sept 2026, 11:28 pmPro-Ukraine Hacking Cat group deploying new malware against Russian targetsThe Record · 14 Sept 2026, 9:45 pmPersonal, Financial Info Exposed in Revolut Data BreachSecurityWeek · 14 Sept 2026, 6:33 pmWebinar: How malicious OAuth apps can lead to Google Workspace breachesBleepingComputer · 14 Sept 2026, 5:45 pm