Japan Digital Agency Breach Exposes 240,000 via VPN Vulnerability
Japan's Digital Agency has disclosed a major data breach affecting approximately 240,000 individuals, with hackers exploiting a known VPN vulnerability to infiltrate its Government Solution Service (GSS) platform. The agency detected the intrusion in late June 2025 after identifying unauthorized access through a maintenance and operations employee's account. A subsequent investigation in July confirmed that the attackers leveraged a publicly disclosed flaw in a VPN product to gain initial entry into the system. Users concerned about exposure in similar incidents can verify their credentials using the email breach checker.
The compromised dataset spans more than 246,000 records, including approximately 236,000 names, 231,000 email addresses, 94,000 phone numbers, and 1,000 physical addresses. According to the agency, the affected information belongs to GSS users, public officials, administrative staff, and partner businesses and individuals. Most of the exposed addresses and phone numbers are tied to government buildings and offices rather than personal residences. Critically, no individual identification numbers or financial account information were compromised in the incident. The compromised VPN product has not been publicly named, but the agency noted the vulnerability had been disclosed prior to exploitation—a gap in patch management that left the door open for attackers. Organizations seeking to evaluate their own external attack surface can run a port scanner to identify exposed services.
In response, the Digital Agency immediately blocked external access to the affected server and suspended the employee account used in the attack. The agency has pledged to strengthen its vulnerability management practices going forward, emphasizing that the exploited flaw had been publicly known before the breach was confirmed. No other systems were compromised, and no information belonging to the general public was exposed, the agency stated. The incident underscores the persistent risk posed by unpatched edge devices and highlights the importance of continuous vulnerability monitoring. Security teams should also evaluate whether internal traffic is being routed through anonymizing services using a VPN/proxy detector to maintain visibility into network access patterns.