Japan’s Digital Agency has reported a cyberattack on government networks that may have resulted in the theft of personal information belonging to approximately 246,000 government staff, contractors, and other personnel. In a report released on September 11, the agency stated that an investigation into its Government Solutions Service (GSS) revealed that third-party hackers compromised Virtual Private Network (VPN) equipment to access personal information contained in files. The agency detected the attack on June 25, when a maintenance and operations account was used to access thousands of files on its servers.
VPN Vulnerability Leads to Unauthorized Access to Government Files
On July 9, it was discovered that a third party had breached the system due to a VPN vulnerability. The maintenance account was immediately disabled, and communication between network equipment and external systems was severed to prevent further access. A subsequent investigation, conducted with the assistance of external security experts, indicated that some files within the network may have been stolen.
The leaked data concerns employees of government departments and agencies utilizing the GSS system, civil servants who have participated in these agencies, and companies and individuals associated with the operations of GSS agencies. Approximately 189,000 records pertain to employees of GSS member agencies and civil servants involved in their activities, while another 57,000 records relate to companies and individuals.
According to Japan’s Digital Agency, the leaked information did not include personal identification numbers, bank account details, or pension numbers. The agency assured the public that personal information of ordinary citizens was not compromised and stated that there have been no reports of the leaked data being misused so far. Authorities are working to identify the specific individuals whose data was exposed and are contacting them directly.
The statement noted that the leaked contact information could be exploited for impersonation or phishing attacks. The agency urged affected individuals to refrain from opening links or attachments and to avoid responding to emails, calls, or text messages claiming to be from government bodies—specifically warning against sharing passwords, verification codes, or credit card details.
Security incidents involving access rights and infrastructure—even those occurring outside government systems—are always a cause for concern. On-chain security platform Blockaid reported that losses in the cryptocurrency sector reached $1 billion (approximately 95.55 billion rupees) in the first half of 2026, marking a period in which the industry suffered some of the worst hacking attacks in history. The blockchain networks Ethereum and Solana were the most heavily impacted by these systemic attacks.
Cryptocurrency is an unregulated digital currency; it is not legal tender and carries market risk. The information provided herein is not intended to be, nor does it constitute, financial advice, trading advice, or any other form of advice or recommendation from NDTV. NDTV shall not be held liable for any losses arising from investments made in reliance on any advice, forecasts, or other information contained in this article.