Particle.news
Download on the App Store

Japan Digital Agency Says 246,000 Government Records May Have Been Exposed

A VPN device flaw let an outsider access files through a maintenance account, raising phishing risks for hundreds of thousands of government workers.

Overview

  • The Digital Agency disclosed on Sept. 11 that an investigation found about 246,000 records may have been exposed after large-scale file access was detected on June 25.
  • Investigators determined on July 9 that a vulnerability in a virtual private network device allowed a third party to use a maintenance and operations account to read and possibly copy files.
  • The potentially exposed files include roughly 236,000 names, 231,000 email addresses, about 94,000 phone numbers and around 1,000 postal addresses, mainly for GSS member agency staff and contractors.
  • The agency says My Number IDs, bank account numbers and pension numbers were not included, no misuse has been found so far, and officials are identifying and notifying affected people individually.
  • The breach highlights a pattern of operational security failures in Japan and could increase phishing and impersonation attempts, so the agency has hired outside specialists and plans reviews of external-connection and vulnerability management practices.