2026-09-12 · view entry permalink →
Japan's Digital Agency: a VPN vulnerability exploited since May went undetected for a month, surfaced only by an anomalous mass file-access alert on a maintenance account, exposing ~246,000 government-personnel records
Japan's Digital Agency confirmed on 2026-09-11 that Government Solution Service (GSS) (the shared PC, network and authentication environment it provisions to government ministries, independent administrative agencies and their contractors) suffered an intrusion that may have exposed personal data on roughly 246,000 individuals (Jiji Press, 2026-09-11): about 236,000 names, 231,000 email addresses, 94,000 phone numbers and 1,000 addresses, with duplication across fields (Piyolog, 2026-09-11). The agency states no National ID, bank-account or pension data was involved, and no general citizen data, only GSS-using-agency staff, associated public servants, and contracted businesses (Rocket Boys Security Measures Lab, 2026-09-11). No secondary misuse has been confirmed as of the disclosure date (Piyolog, 2026-09-11).
The root cause was a third party exploiting a vulnerability in an externally-facing VPN appliance used for maintenance access, gaining a foothold from around late May 2026 (Piyolog, 2026-09-11). The intrusion was not detected from the VPN compromise itself: on 25 June, the agency detected suspicious access from the account of a system maintenance administrator, and only through the subsequent investigation confirmed on 9 July that an external party had repeated unauthorized access since late May (Jiji Press, 2026-09-11). The agency disabled the account and cut the compromised device's external connectivity the same day, then patched the VPN appliance as an initial response (Piyolog, 2026-09-11); roughly two and a half months of investigation with an external forensics firm preceded the public announcement.
At the 2026-09-11 press conference, Digital Minister Matsumoto stated the exploited vulnerability was already known to the agency before the intrusion, rated only "Medium" severity under CVSS, and was being remediated on a severity-based schedule when it was exploited ahead of that fix being applied (Digital Agency Q&A, relayed by Piyolog, 2026-09-11). The agency stated it will review its vulnerability-management approach as a result, without disclosing specifics on what will change (Rocket Boys Security Measures Lab, 2026-09-11).
The agency said it detected suspicious access from the account of a system maintenance administrator on June 25. It then began investigating the incident and found on July 9 that an external third party had repeated unauthorized access since around late May.
"We take it seriously that the incident occurred despite our operations under multi-layered security measures and a 24-hour-a-day, 365-day-a-year surveillance system," Chief Cabinet Secretary Minoru Kihara said at a press conference
悪用された脆弱性の共通脆弱性評価システム(CVSS)における評価は重要度「中(Medium)」程度で、修正プログラムやパッチの適用前に悪用された (translated from Japanese: the exploited vulnerability's CVSS severity rating was around "Medium", and it was exploited before a fix or patch was applied)