240,000 Hit by Data Breach at Japan’s Digital Agency
A data breach at Japan’s Digital Agency exposed the personal information of approximately 240,000 individuals, stemming from a vulnerability exploited via a compromised employee account. The breach targeted data including names, addresses, email addresses, and phone numbers, impacting users, public officials, and businesses utilizing the agency’s Government Solution Service. The agency has taken immediate steps to contain the incident and improve its vulnerability management processes.
Japan’s Digital Agency has disclosed a data breach affecting the personal information of approximately 240,000 individuals. The incident was discovered in late June, after hackers accessed files from its Government Solution Service (GSS) using a maintenance and operations employee’s account.
In July, the investigation determined that a vulnerability in a VPN product had been exploited to access the system. According to the agency, the attackers compromised over 246,000 records containing names (approximately 236,000), addresses (~1,000), email addresses (~231,000), and phone numbers (~94,000). The compromised information belonged to users, public officials, administrative staff, and businesses and individuals working with GSS.
The agency states that the leaked information had been provided by every individual when applying to use GSS, and most of the addresses and phone numbers are associated with the individuals’ workplace, namely a government building or an office. Other personal information, such as individual identification numbers and financial account information, was not affected.
Japan’s Digital Agency blocked external access to the affected server and suspended the employee account used in the attack immediately after confirming the exploitation. While it did not name the exploited VPN product, it said it would strengthen vulnerability management, as the targeted vulnerability had already been publicly disclosed before the attack was confirmed. No other systems were compromised in the attack, and no information of the general public was compromised, the agency said.