Japan's Digital Agency recently revealed a significant data breach that compromised the personal information of around 240,000 individuals. The breach was discovered in late June, when it was found that cybercriminals accessed files from the Government Solution Service using a compromised employee account. Subsequent investigations in July identified that the attackers exploited a vulnerability in a VPN product to gain system access.

The breach affected over 246,000 records, including names, addresses, email addresses, and phone numbers. The information pertains to users, public officials, administrative staff, and entities associated with the Government Solution Service. Notably, the compromised addresses and phone numbers are mostly linked to work locations such as government buildings and offices. Importantly, more sensitive data like individual identification numbers and financial account information remained secure.

Following the breach, Japan's Digital Agency swiftly blocked external access to the compromised server and suspended the implicated employee account. Although the specific VPN product exploited was not disclosed, the agency emphasized plans to enhance vulnerability management, particularly since the targeted vulnerability had been publicly known before the breach. Fortunately, no other systems within the agency were affected, and no data from the general public was compromised.