Japan’s Digital Agency disclosed on Sept. 11 that a cyberattack targeting its Government Solution Service (GSS) may have exposed personal information tied to roughly 246,000 public servants, contractors and other government-linked personnel. The breach occurred after an outside attacker exploited a vulnerability in a virtual private network device, gaining unauthorized access to files containing names, email addresses, phone numbers and some physical addresses.
According to the agency, unusual activity was first detected on June 25, when a maintenance and operations account was used to access a large number of files. An investigation later confirmed on July 9 that a third party had entered through the VPN flaw. The affected maintenance account was disabled that same day, and communications between the compromised equipment and external systems were blocked. A subsequent review with outside security specialists found that some files may have been taken from the network.
The potentially compromised records include approximately 236,000 names, 231,000 email addresses, 94,000 phone numbers and 1,000 physical addresses. Around 189,000 records concern employees of GSS member organizations and other public servants, while roughly 57,000 relate to businesses and individuals working with those organizations. Officials stressed that My Number identification numbers, bank account details, pension numbers and general public data were not included. No misuse has been confirmed, but the agency warned that exposed contact details could be used for impersonation or phishing attempts.
The incident highlights Japan's broader cybercrime problem. National Police Agency figures cited locally recorded 123 ransomware attacks in the first half of 2026, the highest six-month total since tracking began. The disclosure also follows major crypto-linked breaches, including the DMM Bitcoin theft of more than 4,500 BTC worth about $307 million, which authorities and the FBI linked to the North Korean-affiliated TraderTraitor group through a social engineering attack on Ginco. Bybit separately said it blocked more than 30,000 suspicious withdrawals in H1 2026, preventing over $700 million in losses after its $1.46 billion hack in February 2025.
Analysts are watching whether the 246,000 leaked records feed future exploits. Chainalysis has counted more than $30 million stolen in violent crypto-related attacks in the first half of 2026, on track to exceed 2025’s $58 million. The Digital Agency said it will review vulnerability management and improve external connection methods in response.