Overview
- The Digital Agency disclosed on Sept. 11 that an investigation found about 246,000 records may have been exposed after large-scale file access was detected on June 25.
- Investigators determined on July 9 that a vulnerability in a virtual private network device allowed a third party to use a maintenance and operations account to read and possibly copy files.
- The potentially exposed files include roughly 236,000 names, 231,000 email addresses, about 94,000 phone numbers and around 1,000 postal addresses, mainly for GSS member agency staff and contractors.
- The agency says My Number IDs, bank account numbers and pension numbers were not included, no misuse has been found so far, and officials are identifying and notifying affected people individually.
- The breach highlights a pattern of operational security failures in Japan and could increase phishing and impersonation attempts, so the agency has hired outside specialists and plans reviews of external-connection and vulnerability management practices.