Japan’s Digital Agency disclosed that an unidentified external party exploited an unpatched, medium-severity vulnerability in a VPN device supporting the Government Solution Service (GSS), the shared network platform used by 23 ministries and agencies. The intrusion began around late May and was detected on June 25 after suspicious activity and large-scale file access through a system-maintenance administrator account; investigators confirmed the compromise on July 9.
The breach may have exposed personal data for approximately 246,000 government employees, public officials, contractors, and businesses supporting government work. The agency suspended the abused maintenance account, isolated affected equipment, and notified Japan’s privacy regulator; it reported no confirmed data misuse, impact to other systems, or disruption of government services, but warned that exposed contact information could enable targeted phishing and social-engineering impersonation attempts.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
The agency disclosed that files containing personal information may have been exfiltrated, potentially exposing about 246,000 records. The affected information included names, email addresses, telephone numbers, and some physical addresses; no confirmed misuse had been reported.
Japan’s Digital Agency notified the Personal Information Protection Commission about the GSS breach.
The Digital Agency determined that a third party had exploited the VPN flaw to infiltrate GSS. It suspended the maintenance account used in the intrusion and severed external communications from the compromised equipment.
Japan’s Digital Agency detected suspicious activity through a system-maintenance administrator account, involving access to a large volume of files on the GSS network.
An unidentified external party began repeatedly accessing Japan’s Government Solution Service network by exploiting a known medium-severity VPN vulnerability that had not been patched.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.