Japan’s Digital Agency announced Friday that personal information contained in approximately 246,000 records may have been exposed following an unauthorized intrusion into a central government IT platform.
The cyberattack targeted the Government Solution Service, a shared information technology infrastructure used by multiple administrative ministries and public agencies to streamline operations.
VPN Vulnerability and Unauthorized Access Mechanics
Agency officials reported that unauthorized file access was first detected on June 25 after suspicious activity was recorded on an account designated for maintenance and operations personnel.
A technical investigation completed on July 9 confirmed that an external third party had infiltrated the network by exploiting a security vulnerability in a virtual private network device. Authorities subsequently disabled the compromised maintenance account and implemented communication blocks between the affected hardware and external networks to contain the incident.
Scope of Exposed Information and Affected Personnel
The compromised files encompass roughly 189,000 records associated with government employees and staff from affiliated public institutions, along with 57,000 records tied to private companies and individuals conducting business with government entities.
The potential data exposure includes approximately 236,000 individual names, 231,000 email addresses, 94,000 telephone numbers, and 1,000 physical addresses.
Digital Agency officials clarified that the breach did not involve personal data belonging to the general public, nor did it impact national identification numbers, pension records, or banking details.
Ongoing Remediation and Security Warnings
No secondary misuse or unauthorized exploitation of the exposed data has been identified to date. The agency stated that it is contacting potentially impacted individuals and organizations directly while issuing warnings regarding potential phishing or impersonation attempts.
The Digital Agency expressed regret for the incident and confirmed that comprehensive reviews of vulnerability management protocols and external connection controls are underway to prevent future security lapses.

