Summary
Japan’s Digital Agency has disclosed that its Government Solution Service, a shared IT platform used across Japanese government ministries, was compromised after an attacker exploited a vulnerability in a VPN device used for remote maintenance access. The breach exposed approximately 246,000 rows of personal information belonging to government employees, public officials, contractors, and associated businesses. The agency detected the intrusion on June 25, 2026 and confirmed the VPN exploitation method on July 9 — but publicly disclosed the incident on September 11, 78 days after initial detection and 63 days after the intrusion method was confirmed. The agency has not named the VPN product or the specific CVE. No My Number identification numbers, bank account details, pension numbers, or general public data were exposed.
Timeline
| Date | Event |
|---|---|
| June 25, 2026 | Japan Digital Agency detects anomalous large-scale file access from a maintenance and operations staff account |
| July 9, 2026 | Investigation confirms VPN device exploitation; compromised account suspended and affected equipment isolated |
| July 15, 2026 | Japan Digital Agency notifies the Personal Information Protection Commission |
| Sep 11, 2026 | Japan Digital Agency publicly discloses the breach — 78 days after initial detection |
| Sep 15, 2026 | International reporting confirms scope: 246,000 records across 23 government ministries |
What Happened
The Government Solution Service is a shared IT platform used by approximately 23 Japanese government ministries and agencies. The attacker gained initial access by exploiting a known vulnerability — described as medium severity, not a zero-day — in a VPN device used by maintenance and operations personnel for remote access. Using the compromised maintenance account, the attacker conducted large-scale file access detected by the agency’s monitoring systems on June 25.
The potentially exposed records include approximately 236,000 names, 231,000 email addresses, 94,000 telephone numbers, and 1,000 physical addresses. Of the 246,000 total records, approximately 189,000 belong to employees of GSS-using organizations and public officials. The remaining 57,000 records relate to businesses and individuals involved in the operations of those organizations. The agency confirmed the breach was isolated to the GSS system; no other government platforms were compromised.
The 78-day gap between detection and public disclosure is the most operationally significant element of this incident. The agency notified Japan’s Personal Information Protection Commission on July 15, but affected individuals were not informed until September 11. The agency has stated it found no evidence of misuse of the exposed data but warned of elevated phishing and impersonation risk.
Domain Intelligence
digital.go.jp — 93.0
digital.go.jp scores at 93.0 — the highest score published in any TTO bulletin to date. The score reflects the established infrastructure posture of Japan’s Digital Agency as a government domain, consistent with other high-scoring government domains in this publication. A high infrastructure score and a confirmed breach coexist: the score measures domain trust signals, not operational security practices or incident response quality. The breach occurred through a VPN device in the GSS environment, not through digital.go.jp’s own infrastructure.
The Trust Observatory · thetrustobservatory.com · September 15, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026