Incident
Published 2026-09-11
Verified 2026-09-19

Japan Digital Agency: GSS VPN flaw may have exposed ~246,000 personnel records

Japan's Digital Agency (news 11 September 2026; English wire coverage 14 September) says unauthorised access to Government Solution Service (GSS) may have exposed about 246,000 personal-information records. Detection on 25 June 2026 (large-scale file access via a maintenance/operations account); on 9 July investigators found a third party had used a vulnerability in a network-connected VPN device to enter the system. That day the agency suspended the account and cut external communication from the compromised equipment. Possible leaked fields include names, email addresses, phone numbers, and addresses of GSS-using agency staff, associated public officials, and contractors/individuals who worked with those agencies. Agency says My Number, bank accounts, and pension numbers were not in the exposed set; no secondary misuse confirmed at publication. Q&A: vulnerability was previously published (not a zero-day) with a medium CVSS rating; product/CVE withheld for security. Primary: Digital Agency notice; secondary: BleepingComputer.

Product
Government Solution Service (GSS) — VPN / network-connected device (vendor not named)
Versions
n/a (agency: medium-severity previously disclosed VPN flaw; CVE/product not published)
Exploited in Australia?
unknown
Patch to
Government/enterprise VPN estates: prioritise medium-rated VPN CVEs on internet-facing gear; rotate maintainer credentials after anomalous file-access; notify affected staff about phishing risk

Primary: Digital Agency (Japan) — GSS unauthorised access / possible personal information leak (11 Sep 2026) · Vendor: Digital Agency Q&A on the GSS incident · BleepingComputer (14 Sep 2026)

breaches identity network