A patchable VPN flaw exposed 246,000 Japanese government records

A shared platform serving 23 ministries was breached through an unpatched VPN, with disclosure coming 78 days after detection.

CSBadmin
2 Min Read

Roughly 246,000 records tied to Japanese government workers may be in outside hands after attackers slipped through a VPN into a platform shared by 23 ministries and agencies. Japan’s Digital Agency disclosed the breach on September 11.

Staff spotted the trouble on June 25, when an unusually large set of files was pulled using a maintenance worker’s credentials. The VPN route was confirmed on July 9. That same day, officials disabled the account and severed the compromised hardware from external networks. Disclosure came 78 days after the first signal.

Names account for about 236,000 of the exposed records, alongside 231,000 email addresses, 94,000 phone numbers, and roughly 1,000 physical addresses. Some 189,000 records belong to ministry and agency personnel, with 57,000 more linked to contractors. My Number IDs, bank details, and pension numbers were not part of the set.

The agency has not named the VPN product. What it did confirm is that the flaw carried only a medium severity rating and was never a zero-day. A fix was already available, a reminder of what happens when known, patchable gaps linger on shared infrastructure.

Japan’s privacy regulator heard about the incident on July 15. Officials pointed to the difficulty of tracing the intrusion and working out which data was touched.

No abuse of the data has surfaced. Even so, the leaked names, emails, and phone numbers give phishers good material, and the agency is warning that it never asks for passwords or payments.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.