Japan's Digital Agency says VPN flaw exposed 246,000 personnel records
by Bill Toulas · BleepingComputerJapan’s Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees.
The agency says that the attacker gained initial access by exploiting a vulnerability in a VPN device used by the Government Solution Service (GSS).
An investigation started on June 25, after the agency detected a large-scale file access from the account of a maintenance and operations staff member.
“On July 9th, it was discovered that a third party had used a vulnerability in a network-connected device (VPN) to gain access to the system and gain unauthorized access,” reads the announcement.
“On the same day, we suspended the account of the maintenance and operations personnel in question, cut off communication between the compromised equipment and the outside world, and prevented further unauthorized access.”
It is unclear what VPN product was affected or the vulnerability exploited in the breach. However, the Japanese agency said in a separate Q&A that the issue had a medium severity rating and was not a zero-day.
The investigation revealed that the following data may have been exposed:
- 236,000 names
- 231,000 email addresses
- 94,000 telephone numbers
- 1,000 physical addresses
Exposed individuals include government employees, public officials, and associated businesses and individuals who use the GSS system.
However, the incident did not expose personal data of the general public, and the potentially compromised information does not include My Number identification numbers, bank-account details, or pension numbers.
Also, the agency has not detected any cases of actual misuse of the impacted information, but still warned about the elevated risk of impersonation and phishing, urging people not to open links or attachments in unsolicited communications.
The Digital Agency reminded people that it will never ask for passwords or credit card information via email or phone.
Affected individuals will be contacted directly, and the agency also set up a dedicated support line.
The agency notified Japan’s Personal Information Protection Commission on July 15, and clarified that the delay in disclosing the incident to the public was due to the complexity of determining the intrusion path, identifying potentially affected information, and establishing who was affected.
The agency says the impact was limited to the affected system, with no confirmed unauthorized access, data leakage, or comparable breaches affecting other systems. It also noted that the incident and response operations didn’t impact government services availability.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.