LIVE · cybersecurity feed
Live wire
breach

Japan's Digital Agency says VPN flaw exposed 246,000 personnel records

Japan's Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees. [...]

zeroday.news ·

Japan's Digital Agency has confirmed a data breach that potentially exposed personal information for approximately 246,000 individuals, primarily government employees and associated personnel. The breach originated from an exploited vulnerability in a VPN device utilized by the Government Solution Service (GSS).

The agency initiated an investigation on June 25 after detecting unusual large-scale file access from a maintenance and operations staff account. By July 9, it was determined that a third party had leveraged a vulnerability in a network-connected VPN device to gain unauthorized system access. On the same day, the compromised staff account was suspended, and communication between the affected equipment and external networks was severed to prevent further unauthorized activity.

While the specific VPN product and vulnerability exploited were not disclosed, the Digital Agency indicated that the flaw was not a zero-day and had a medium severity rating. The investigation revealed that the exposed data may include 236,000 names, 231,000 email addresses, 94,000 telephone numbers, and 1,000 physical addresses.

The individuals potentially affected include government employees, public officials, and business partners or individuals who interact with the GSS system. The agency clarified that the incident did not impact the personal data of the general public. Crucially, sensitive identifiers such as My Number identification numbers, bank account details, or pension numbers were not exposed.

As of the agency's announcement, no instances of actual misuse of the compromised information have been detected. However, the Digital Agency has issued a warning regarding an elevated risk of impersonation and phishing attempts. Individuals are advised to exercise caution with unsolicited communications and avoid opening suspicious links or attachments. The agency also reiterated that it will never request passwords or credit card information via email or phone.

Affected individuals will be contacted directly, and a dedicated support line has been established to assist them. The Personal Information Protection Commission was notified on July 15. The agency explained that the delay in public disclosure was due to the complex process of identifying the intrusion path, determining the scope of affected information, and identifying the impacted individuals.

The Digital Agency confirmed that the impact of the breach was contained to the specific affected system. There has been no evidence of unauthorized access, data leakage, or similar breaches affecting other government systems. Furthermore, the incident and the subsequent response operations did not disrupt the availability of government services.

breachvulnerability
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

malware

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

malware

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

'Enemies of the regime' on notice

patch

Before You Patch. Why Patch Reliability Matters for Confident Deployment

Executive Summary Microsoft’s September 2026 security updates, KB5124008 and KB5124012, have been linked to USB audio failures on some Windows systems, highlighting the operational risk that can accompany security patching. Qualys TruRisk Eliminate classified both updates as Low Reliability, signaling the need for additional validation before production deployment. Patch Reliability helps IT and s