Japan government network breach exposes 246,000 records
Japan's Digital Agency disclosed on Sept. 11 that a cyberattack on its Government Solution Service (GSS) — a shared network for 23 ministries — may have leaked personal data of 246,000 civil servants and contractors. An attacker exploited a known vulnerability in a VPN device to access files between late May and late June, per the agency. The breach was detected June 25 but only confirmed July 9.
Bottom line — Names, emails, and phone numbers of 246,000 government personnel are at risk, per the Digital Agency.
Go deeper (8)
- The intruder entered through a vulnerability in VPN equipment; the agency said it was aware of the flaw but had not yet applied a patch, per the Jiji Press report.
- Potentially leaked data includes 236,000 names, 231,000 email addresses, 94,000 phone numbers, and 1,000 physical addresses, according to the Digital Agency.
- No My Number identification numbers, bank account details, or pension numbers were compromised, the agency stated.
- Chief Cabinet Secretary Minoru Kihara called the incident a serious matter, saying the system operated under multi-layered security and 24/7 monitoring, per Jiji Press.
- Digital Minister Hisashi Matsumoto apologised at a press conference and said the agency would review vulnerability management and improve external connection procedures, per The Star.
- Japan recorded 123 ransomware attacks in the first half of 2026, the highest six-month total since tracking began, per the National Police Agency via the Insurance Journal.
- The GSS was introduced in 2021 to replace separate ministerial networks during the COVID-19 telework push and serves about 154,000 users across 23 organisations, per The Star.
- Critics argue the breach reflects a gap between Japan's 'zero trust' rhetoric and systemic gaps: a single maintenance account held access to shared infrastructure, per an analysis in Opinion Nigeria.