Japan’s Digital Agency disclosed the case on September 11. The attack hit its shared GSS work system. The agency first saw odd file access on June 25. Someone used a staff account to access many files on a server.
On July 9, investigators found that a third party had used a VPN flaw to get in. The agency shut the staff account that day. It also cut the hacked device off from outside links, fixed the VPN flaw, and changed key login data. The agency says it has not seen more bad access since.
The VPN brand and flaw number remain secret. The agency says sharing those details could add more risk.
The flaw was known before the attack
The VPN flaw was not a zero-day. The agency says researchers had disclosed the flaw before the attack. It had also started work to fix it. But officials had not installed the fix when the attacker used the flaw.
The agency gave the flaw a medium risk score under CVSS. CVSS is a common scale used to rate software flaws. Here, the VPN device gave an attacker a way into GSS. The system serves many government groups.
The agency says it will review how it tracks and fixes flaws. It also plans to review outside links into GSS. The incident also reflects a wider security problem with vulnerable VPN systems. Security experts have warned that hackers are increasingly targeting VPN flaws as a primary ransomware entry point, making timely patching critical for organizations that rely on remote-access systems.
About 246,000 records may be exposed
The agency says the incident may have caused the exposure of 246,000 records. But it’s not clear yet if it’s a case of data theft or just a data leak.
About 189,000 records concern staff at GSS user groups and public workers who worked with them. Another 57,000 records concern firms and people who worked with those groups.
The files may hold about 236,000 names. They may also include 231,000 email addresses. About 94,000 phone numbers may appear in the files. So may about 1,000 addresses. These counts overlap. One record can have a name, email and phone number at the same time.
The agency says people used much of the phone and address data for work. Some entries listed office sites or work contact details. The files did not hold My Number IDs. They also did not hold bank account data or pension numbers.
The agency says the data did not cover the public at large. It did, however, cover some firms and people who worked with government offices. The possible data also covers some business users. That includes people who joined web meetings run by GSS user agencies.
The agency uses a broad count to protect people. If it cannot rule out access, it counts the data as at risk. That makes the 246,000 figure a possible exposure count. It is not a confirmed theft count.
No misuse has been found
The agency says it has found no misuse of the data so far. It still warns that the data could help scams. A scammer could use names and work contacts to send fake mail. They could also pose as a government worker.
The agency told people to watch for odd emails, calls, and texts. It also said not to open strange links or files. People should not enter passwords or card data after an odd request. The agency says it will never ask for such data by phone or email.
Also, the agency has set up a helpline for people whose data may be at risk. However, it didn’t name the attacker; it has not tied the case to ransomware or a known hacking group. Outside security experts helped the agency assess the possible leak and narrow the scope of affected data.
The public disclosure took weeks
The agency saw the file access on June 25. It found the VPN link on July 9. It told Japan’s privacy watchdog on July 15. The agency then made the case public on September 11. That gap has drawn attention.
The agency says in a separate Q&A that it needed time to trace the entry path. It also needed to find what data the attacker may have reached. Officials had to work out who may be affected with the help of outside experts.
The agency says it went public after it had enough facts to explain the case. It also says the review is still underway.
Impact appears limited to GSS
According to the disclosure, the attack did not stop government work. Also, no other system shows the same type of breach.
GSS uses a Zero Trust design. Even so, the agency says the attack may have caused a data leak. The next move is to tighten flaw checks. The agency also plans to review how outside users reach its systems.
It will add steps to limit harm if an attacker gets in again. The objective here isn’t just to block attacks; it wants to limit what an intruder can access.
For now, the most established fact is that about 246,000 records may be at risk. Japan has not confirmed that all of those records left the system. The agency is still checking the case and reaching out to people who may be affected.