Possible GSS Data Leak After VPN Vulnerability Exploited in Japan

Japan’s Digital Agency is investigating the possible leak of approximately 246,000 records from the government’s GSS service after a VPN device vulnerability was exploited.

The possible GSS data leak concerns the Government Solution Service, a government shared-work service. On September 11, Japan’s Digital Agency said that unauthorized access may have resulted in the leak of approximately 246,000 records containing personal information. According to the agency, the attacker gained access by exploiting a vulnerability in a VPN device.

The agency discovered the unauthorized access on June 25. It confirmed on July 9 that the attacker had exploited a VPN vulnerability. This is therefore not merely a theoretical vulnerability: according to the agency, it was actually exploited in this environment to gain unauthorized access.

Possible GSS data leak may affect 246,000 records

Two groups of records may be affected. The first consists of approximately 189,000 records belonging to employees of organizations that use GSS. Another roughly 57,000 records concern individuals or companies involved in the work of these organizations.

The data that may have been exposed mainly includes names, email addresses and telephone numbers. To a lesser extent, it may also include addresses. The agency also said that the affected data does not contain My Number numbers, bank account information or pension insurance numbers.

The notice refers to the possibility of a leak, not to the confirmed transmission of every one of the approximately 246,000 records outside GSS systems. The investigation is ongoing, and the scope of the incident or conclusions about any misuse of the data may still change.

VPN remediation and device isolation

Digital Agency said it applied a fix to the VPN device, blocked the relevant account and cut off external communication from the compromised device. According to the agency, it has not detected any further unauthorized access or suspicious communication since then.

The agency has not disclosed the specific vulnerability, CVE identifier, vendor or version of the affected VPN device. Based on the available information, it is therefore not possible to independently determine the exact technical attack vector or the extent of any potential risk to other organizations using the same solution.

Work contacts could be used for targeted phishing

Although secondary misuse of the data had not been confirmed as of September 11, the combination of names and business contact information could be useful in targeted phishing or impersonation communications aimed at public-sector employees and their associates.

Affected organizations should monitor unusual messages, especially requests to change login credentials, open attachments or share internal information. Digital Agency has not yet reported a confirmed campaign using data from this incident.

What happens next

Further findings should show whether the agency discloses the vendor’s identity, the specific CVE or the VPN product version. The outcome of the ongoing investigation will also be important, including the answer to whether the files were actually exfiltrated.

Possible changes to the number of affected records, the method of individually contacting affected individuals, and notices about phishing activity or regulatory actions should also be monitored.

Sources

Verified and updated: 09/15/2026 06:28

Sharing