Japan Digital Agency: GSS VPN flaw may have exposed ~246,000 personnel records
Japan's Digital Agency (news 11 September 2026; English wire coverage 14 September) says unauthorised access to Government Solution Service (GSS) may have exposed about 246,000 personal-information records. Detection on 25 June 2026 (large-scale file access via a maintenance/operations account); on 9 July investigators found a third party had used a vulnerability in a network-connected VPN device to enter the system. That day the agency suspended the account and cut external communication from the compromised equipment. Possible leaked fields include names, email addresses, phone numbers, and addresses of GSS-using agency staff, associated public officials, and contractors/individuals who worked with those agencies. Agency says My Number, bank accounts, and pension numbers were not in the exposed set; no secondary misuse confirmed at publication. Q&A: vulnerability was previously published (not a zero-day) with a medium CVSS rating; product/CVE withheld for security. Primary: Digital Agency notice; secondary: BleepingComputer.
- Product
- Government Solution Service (GSS) — VPN / network-connected device (vendor not named)
- Versions
- n/a (agency: medium-severity previously disclosed VPN flaw; CVE/product not published)
- Exploited in Australia?
- unknown
- Patch to
- Government/enterprise VPN estates: prioritise medium-rated VPN CVEs on internet-facing gear; rotate maintainer credentials after anomalous file-access; notify affected staff about phishing risk
Primary: Digital Agency (Japan) — GSS unauthorised access / possible personal information leak (11 Sep 2026) · Vendor: Digital Agency Q&A on the GSS incident · BleepingComputer (14 Sep 2026)
