Japan’s Digital Agency says unauthorised access to its Government Solution Service (GSS) may have led to the leakage of around 246,000 personal records, after attackers exploited a vulnerability in a virtual private network (VPN) device and used a maintenance operations account to access files across the shared platform.
According to details circulated by communications firm McGallen & Bolden, the Digital Agency disclosed the incident on 11 September. The GSS is described as a shared working environment used across ministries and agencies. The attackers are believed to have exploited the VPN vulnerability around late May and then leveraged the maintenance operations account to access files “at scale”.
The agency detected suspicious activity on 25 June, confirmed the cause on 9 July and disabled the account and external connections the same day, the message said.
Information that may have been exposed includes names, email addresses and phone numbers for public officials, contractors and business operators. The Digital Agency said no My Number identifiers, bank details or pension numbers were exposed.
Keeper Security APAC senior vice president and Japan country manager Takanori Nishiyama said the incident highlights risks associated with privileged accounts that have broad, persistent access. “Identity is the perimeter for government systems today. A maintenance account with broad standing access widens the blast radius of any single exploited device,” Nishiyama said in comments provided for background.
Nishiyama also cited Japan’s National Police Agency 2025 threat report, which he said found VPN devices accounted for two-thirds of ransomware intrusion routes, ahead of remote desktop and email. He added that the same report found that 43.7% of the devices used for entry had the latest patch applied, which he said points to issues such as stolen credentials, weak passwords and misconfiguration.
The Digital Agency has pledged to review vulnerability management and external connections, according to the message. Nishiyama said privileged access controls, including least-privilege, just-in-time access and multi-factor authentication, are needed to limit lateral movement and contain impact following initial compromise.

