CTIPilot

Japan Digital Agency GSS unauthorized-access incident (2026-09)

incident · incident:japan-digital-agency-gss-breach-2026-09

VPN-vulnerability intrusion into Japan's government-wide Government Solution Service (GSS) shared IT platform, exploited from around late May 2026 and detected 2026-06-25 via anomalous privileged-account file access; disclosed 2026-09-11 with ~246,000 potentially exposed personal-data records (Digital Agency, 2026-09-11).

Aliases: デジタル庁 GSS 不正アクセス

Coverage timeline
1
first 2026-09-12 → last 2026-09-12
Peak priority
notable
1 notable
Sources cited
3
3 hosts
Sections touched
1
active-threats
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
3
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques

ATT&CK techniques

3 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-09-12/japan-digital-agency-gss-vpn-breach-maintenance-account · ATT&CK page ↗

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-09-12/japan-digital-agency-gss-vpn-breach-maintenance-account · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-09-12/japan-digital-agency-gss-vpn-breach-maintenance-account · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-09-12/japan-digital-agency-gss-vpn-breach-maintenance-account · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-09-12/japan-digital-agency-gss-vpn-breach-maintenance-account · ATT&CK page ↗

Collection TA0009

T1005Data from Local System×1

Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.

Evidence: 2026-09-12/japan-digital-agency-gss-vpn-breach-maintenance-account · ATT&CK page ↗

Story timeline

  1. 2026-09-12Japan's Digital Agency: a VPN vulnerability exploited since May went undetected for a month, surfaced only by an anomalous mass file-access alert on a maintenance account, exposing ~246,000 government-personnel records
    active-threatsThe catch was the file-access volume, not the VPN exploit itself, and the flaw was already known and mid-remediation when it was used

Where this entity is cited

  • active-threats1

Source distribution

  • nippon.com1 (33%)
  • piyolog.hatenadiary.jp1 (33%)
  • rocket-boys.co.jp1 (33%)

explore in graph

Entries about Japan Digital Agency GSS unauthorized-access incident (2026-09) (1)

2026-09-12 · view entry permalink →

NOTABLENATOB1

Japan's Digital Agency: a VPN vulnerability exploited since May went undetected for a month, surfaced only by an anomalous mass file-access alert on a maintenance account, exposing ~246,000 government-personnel records

Japan's Digital Agency confirmed on 2026-09-11 that Government Solution Service (GSS) (the shared PC, network and authentication environment it provisions to government ministries, independent administrative agencies and their contractors) suffered an intrusion that may have exposed personal data on roughly 246,000 individuals (Jiji Press, 2026-09-11): about 236,000 names, 231,000 email addresses, 94,000 phone numbers and 1,000 addresses, with duplication across fields (Piyolog, 2026-09-11). The agency states no National ID, bank-account or pension data was involved, and no general citizen data, only GSS-using-agency staff, associated public servants, and contracted businesses (Rocket Boys Security Measures Lab, 2026-09-11). No secondary misuse has been confirmed as of the disclosure date (Piyolog, 2026-09-11).

The root cause was a third party exploiting a vulnerability in an externally-facing VPN appliance used for maintenance access, gaining a foothold from around late May 2026 (Piyolog, 2026-09-11). The intrusion was not detected from the VPN compromise itself: on 25 June, the agency detected suspicious access from the account of a system maintenance administrator, and only through the subsequent investigation confirmed on 9 July that an external party had repeated unauthorized access since late May (Jiji Press, 2026-09-11). The agency disabled the account and cut the compromised device's external connectivity the same day, then patched the VPN appliance as an initial response (Piyolog, 2026-09-11); roughly two and a half months of investigation with an external forensics firm preceded the public announcement.

At the 2026-09-11 press conference, Digital Minister Matsumoto stated the exploited vulnerability was already known to the agency before the intrusion, rated only "Medium" severity under CVSS, and was being remediated on a severity-based schedule when it was exploited ahead of that fix being applied (Digital Agency Q&A, relayed by Piyolog, 2026-09-11). The agency stated it will review its vulnerability-management approach as a result, without disclosing specifics on what will change (Rocket Boys Security Measures Lab, 2026-09-11).

The agency said it detected suspicious access from the account of a system maintenance administrator on June 25. It then began investigating the incident and found on July 9 that an external third party had repeated unauthorized access since around late May.

"We take it seriously that the incident occurred despite our operations under multi-layered security measures and a 24-hour-a-day, 365-day-a-year surveillance system," Chief Cabinet Secretary Minoru Kihara said at a press conference

Jiji Press (via Nippon.com) 2026-09-11

悪用された脆弱性の共通脆弱性評価システム(CVSS)における評価は重要度「中(Medium)」程度で、修正プログラムやパッチの適用前に悪用された (translated from Japanese: the exploited vulnerability's CVSS severity rating was around "Medium", and it was exploited before a fix or patch was applied)

Piyolog (Piyokango), Japanese security incident-tracking blog 2026-09-11
incident12 Sep 04:09Zmulti-sourceOpen finding ↗