Japan's Digital Agency has confirmed a substantial data breach affecting the Government Solution Service (GSS), a shared IT platform used across multiple ministries and government bodies, following an attack on a VPN appliance that exploited a vulnerability to gain unauthorized access to internal servers This article explores digital jp compromised. . Japan's Digital Agency Data Breach Based on the agency's official statement, suspicious activity was first detected on June 25, 2026, when a large volume of files on a GSS server was accessed using the credentials of a maintenance and operations staff member.

Notably, security researchers reported that the exploited VPN flaw was rated medium severity, not a zero-day, and a patch was available before the attackers took advantage of it, raising questions about the agency’s patch management practices.

GSS unauthorized access overview (Image Source: digital.go.jp) The compromised files reportedly contained names, email addresses, phone numbers, and physical addresses tied to approximately 189,000 employees and public officials from GSS user organizations, as well as about 57,000 records belonging to contractors and businesses supporting those agencies. The agency will contact affected individuals individually as identification efforts continue. The roughly 78-day gap between initial detection and public disclosure has drawn scrutiny, underscoring broader concerns about the security of internet-facing VPN infrastructure used across government and enterprise networks worldwide.