Japan's Digital Agency disclosed a breach affecting approximately 246,000 records of government staff and contractors on Friday, September 11. The intrusion exposed names, email addresses, phone numbers, and some physical addresses of civil servants and contractors who use the shared Government Solution Service platform.
Scope of Exposed Data
The breach leaked 236,000 names, 231,000 email addresses, 94,000 phone numbers, and 1,000 physical addresses from the GSS platform used by Japanese ministries and agencies nationwide.
How the Breach Occurred
The Digital Agency detected unusual activity on June 25 after a maintenance and operations contractor account accessed a large number of files. Investigators determined the intrusion began in late May. A VPN device vulnerability was identified as the likely entry point. The agency suspended the account and disconnected the compromised equipment from the external network on the day they issued an update on July 9.
Japan's Cybersecurity Challenge
Japan ranks among the ten most targeted countries for cyberattacks globally, according to CloudSEK's 2026 cybercrime report. The breach is notable because the Digital Agency was established in 2021 specifically to modernize and secure government information technology systems.
The country has experienced multiple significant breaches in recent years. In July, a KDDI breach exposed approximately 12.23 million email addresses and 7.61 million passwords. A 2023 attack attributed to Chinese hackers targeted Japan's National Center of Incident Readiness and Strategy for Cybersecurity.
Ongoing Monitoring
The Digital Agency stated that the exposed data has not been confirmed in any current exploits or campaigns. However, security analysts will continue monitoring whether the stolen names and email addresses appear in future attacks.


