"On July 9th, it was discovered that a third party had used a vulnerability in a network-connected device (VPN) to gain access to the system and gain unauthorized access," the Digital Agency said in its public announcement.
Digital Agency investigation and timeline
The Digital Agency began an internal investigation on June 25 after it detected what it described as "large-scale file access" from the account of a maintenance and operations staff member. The agency traced the activity and, by July 9, concluded that a third party had exploited a vulnerability in a VPN device to gain unauthorized access to a Government Solution Service (GSS) system. On that same day the agency suspended the maintenance account, severed communications between the compromised equipment and the outside world, and took steps to prevent further access.
VPN device vulnerability and the Government Solution Service
The agency says the attacker’s initial foothold came through a vulnerability in a VPN device used by the GSS. The public statement made clear the specific VPN product and the precise vulnerability exploited remain unspecified: "It is unclear what VPN product was affected or the vulnerability exploited in the breach." The agency added in a separate Q&A that the issue was rated medium severity and was not a zero-day, indicating the vulnerability was known rather than previously unreported.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadScale and content of exposed records
Investigators identified roughly 246,000 rows of records that may have been exposed. The Digital Agency listed the potentially compromised fields with specific counts:
- 236,000 names
- 231,000 email addresses
- 94,000 telephone numbers
- 1,000 physical addresses
Those affected include government employees, public officials, and associated businesses and individuals who use the GSS system. The agency also emphasized what was not exposed: the incident did not involve personal data of the general public, and the potentially compromised information does not include My Number identification numbers, bank-account details, or pension numbers.
Agency response: containment, notification, and public guidance
The Digital Agency reported that it has not detected any confirmed cases of misuse of the impacted information. Nevertheless, it warned of an elevated risk of impersonation and phishing and urged recipients not to open links or attachments in unsolicited communications. The agency reminded the public that it will never ask for passwords or credit card information via email or phone.
Concretely, the agency said affected individuals will be contacted directly and that it has established a dedicated support line. It notified Japan’s Personal Information Protection Commission on July 15. The agency explained the gap between initial discovery and public disclosure by citing the complexity of determining the intrusion path, identifying potentially affected information, and establishing who was affected.
Officials also stated the impact was limited to the affected GSS system. They reported no confirmed unauthorized access, data leakage, or comparable breaches affecting other systems, and that incident and response operations did not disrupt the availability of government services.
What this means for government employees, associated businesses, and security teams
- Government employees and public officials: Expect direct contact from the Digital Agency if your records were among the potentially exposed rows; follow the agency’s guidance not to respond to unsolicited requests for credentials or financial details.
- Associated businesses and individuals who use GSS: Monitor communications for targeted impersonation or phishing attempts tied to the exposed email and phone records, and use the agency’s dedicated support line if you receive unusual contacts.
- Government and IT security teams operating GSS-like services: The breach underlines the risk of VPN-device vulnerabilities being used to pivot into maintenance accounts. Teams will likely review remote-access device configurations, account privileges for maintenance personnel, and detection of large-scale file access patterns — actions the Digital Agency itself employed during the response.
The Digital Agency’s public record furnishes a clear chain: detection of anomalous activity on June 25, attribution of access to a VPN-device vulnerability by July 9, immediate containment steps that day, notification to the Personal Information Protection Commission on July 15, and continued outreach to affected people. What remains unresolved—and central to future risk reduction—is the identity of the VPN product and the exact vulnerability exploited. That detail, the agency says, is currently unknown to the public.
For now, the agency’s posture is containment and direct remediation for affected accounts, coupled with warnings aimed at preventing follow-on fraud from exposed contact details. The agency’s next visible steps will be the notifications to affected individuals and any further technical detail it chooses to publish about the vulnerability that enabled the intrusion.




