---
title: Japanese government system breached via unpatched VPN vulnerability
url: https://www.dataloco.com/en/japanese-government-system-breached-via-unpatched-vpn-vulnerability
published: 2026-09-19T13:21:17+00:00
language: en
section: Security
source: https://www.dailysecu.com/news/articleView.html?idxno=208517
organizations: Digital Agency, Government Solution Service
publisher: Dataloco
---

# Japanese government system breached via unpatched VPN vulnerability

The Japanese government confirmed that a shared administrative system used by multiple central ministries was hacked, resulting in the potential leakage of personal data for approximately 240,000 individuals. The breach occurred when an attacker exploited a known vulnerability in a Virtual Private Network device connected to the internet, allowing unauthorized access to the internal network.

The Digital Agency disclosed the external intrusion into the Government Solution Service on September 11. The incident was initially detected on June 25 when unusual activity was observed in the accounts of system maintenance personnel accessing large volumes of stored files. An investigation determined that a third party had breached the system on July 9 by exploiting the VPN vulnerability. On the same day, the agency suspended the compromised maintenance account and blocked communication between the affected equipment and external networks.

The potentially leaked data includes information for approximately 189,000 government employees and officials, as well as approximately 57,000 business operators and individuals involved in government work. The data types comprise names for about 236,000 records, email addresses for about 231,000, phone numbers for about 94,000, and addresses for about 1,000. Most phone numbers and addresses were for official government business rather than personal residential details. The government stated that My Number identifiers, financial account information, and pension numbers were not found in the potentially leaked materials, and no general public personal data was included.

The vulnerability exploited in this attack had been publicly disclosed prior to the incident. The Digital Agency noted that the vulnerability carried a medium risk rating under the Common Vulnerability Scoring System. Although internal protocols aimed to address the issue faster than standard benchmarks, the attacker exploited the flaw before the patch was applied. The agency has since applied the patch, changed authentication credentials for related accounts, and blocked external communications from the compromised equipment. No new abnormal access or suspicious communications have been detected since these measures were taken.

The Government Solution Service serves as a common administrative foundation for Japanese government ministries, providing shared workstations, networks, software, and security environments. As of February 2026, approximately 53,000 people across 18 government agencies use the system, with plans to expand usage to approximately 280,000 users. The agency reported the incident to the Personal Information Protection Commission on July 15 and officially disclosed it on September 11. As of the September 12 update, no secondary damage or misuse of the personal data has been confirmed, and the agency is notifying affected individuals sequentially. The agency declined to disclose the specific VPN vendor, the Common Vulnerabilities and Exposures identifier, or the attack group responsible, citing concerns that such details could compromise future system security.

## This story in other languages

- [Italiano](https://www.dataloco.com/it/hacker-colpisce-il-governo-giapponese-possibile-fuga-di-246000-dati-personali)
- [Español](https://www.dataloco.com/es/el-gobierno-de-japon-sufre-hackeo-y-posible-filtracion-de-246000-datos-personales)
- [Français](https://www.dataloco.com/fr/le-gouvernement-japonais-victime-dun-piratage-environ-246-000-donnees-personnelles-potentiellement-compromises)
- [Nederlands](https://www.dataloco.com/nl/japanse-overheid-getroffen-door-hack-waarbij-persoonlijke-gegevens-van-246000-personen-zijn-gelekt)
- [Русский](https://www.dataloco.com/ru/iaponskoe-pravitelstvo-soobshhilo-ob-utecke-dannyx-iz-sistemy-gss-iz-za-uiazvimosti-vpn)
- [עברית](https://www.dataloco.com/he/246000)
- [Deutsch](https://www.dataloco.com/de/hackerangriff-auf-japanische-regierungsplattform-fuhrt-zu-moglichem-datenabfluss)
- [Polski](https://www.dataloco.com/pl/wyciek-danych-z-japonskiego-systemu-rzadowego-przez-luke-w-vpn)
- [العربية](https://www.dataloco.com/ar/akhtrak-ntham-hkomy-yabany-yody-al-ahtmal-tsryb-byanat-246-alf-shkhs)
- [Svenska](https://www.dataloco.com/sv/hackerattacker-har-kommit-at-personuppgifter-fran-japanska-regeringens-gemensamma-arbetssystem)
- [Norsk](https://www.dataloco.com/no/hacking-av-japansk-myndighetssystem-kan-ha-lekket-personopplysninger-for-246-000-personer)
