Ethical Hacking News
A non-zero-day VPN flaw exposed 246,000 records at risk on Japan's government shared network platform. The breach was discovered on June 25, 2026, and confirmed on July 9, 2026, due to a vulnerability in a VPN device that serves the Government Solution Service (GSS) network. The potentially exposed data includes names, email addresses, and phone numbers of employees and contractors, which could enable targeted phishing and social engineering. The incident highlights the risk of leaving a known, patchable flaw unaddressed on infrastructure shared by 23 ministries.
246,000 records are at risk due to a non-zero-day VPN flaw. The vulnerability was discovered on June 25, 2026, and the breach was confirmed on July 9, 2026. Personal information of 236,000 names, 231,000 email addresses, 94,000 phone numbers, and 1,000 physical addresses may have been leaked. The VPN flaw was rated medium severity and wasn't a zero-day. No confirmed misuse of the exposed data has been reported, but it could enable targeted phishing and social engineering. The breach highlights systemic challenges in patching and access management across Japan's public sector infrastructure.
A recent cyberattack on Japan's government shared network platform has left 246,000 records at risk due to a non-zero-day VPN flaw. The vulnerability, which was not a zero-day exploit, was discovered on June 25, 2026, and the breach was confirmed on July 9, 2026. The attack followed a straightforward path, where an outsider exploited a vulnerability in a VPN device that serves the Government Solution Service (GSS) network, accessed the system using a maintenance and operations staff member's account, and browsed a large number of files on the server.
The breach was detected by Japan's Digital Agency, which connects 23 Japanese ministries and agencies through shared IT infrastructure. The agency confirmed that the personal information that may have been leaked pertains to employees of various ministries and agencies that use GSS (hereinafter referred to as "GSS user organizations") and those involved in their work. The potentially exposed data breaks down to roughly 236,000 names, 231,000 email addresses, 94,000 phone numbers, and approximately 1,000 physical addresses.
The VPN flaw was rated medium severity and wasn't a zero-day. A patch was already available when attackers exploited it, but the agency hasn't revealed the VPN product or the flaw. The Digital Agency said the delay came from the difficulty of tracing the attack, assessing the affected data, and identifying those involved.
The incident also shows the risk of leaving a known, patchable flaw unaddressed on infrastructure shared by 23 ministries. No confirmed misuse of the exposed data has been reported. However, the leaked names, email addresses and phone numbers could enable targeted phishing and social engineering, including scams impersonating Japan's Digital Agency.
The agency will contact affected people directly and warns that it will never request passwords or payments by email or phone. The breach is one in a series of significant cybersecurity incidents affecting Japanese institutions. NISC, Japan's National Cyber Incident Readiness and Strategy Center, disclosed a breach in 2023 that affected its email system. Japan Aerospace Exploration Agency (JAXA) reported unauthorized access to its systems in 2024.
The pattern points to systemic challenges in patching and access management across Japan's public sector infrastructure rather than isolated failures. The Digital Agency's planned remediation includes improved vulnerability management and changes to external connection methods, which are the right responses to the immediate incident. Whether they address the underlying governance question is harder to assess from the public advisory alone.
Related Information:
https://www.ethicalhackingnews.com/articles/Japans-Government-Shared-Network-Platform-Exposed-246000-Records-at-Risk-Due-to-Non-Zero-Day-VPN-Flaw-ehn.shtml
https://securityaffairs.com/199090/security/non-zero-day-vpn-flaw-left-japan-government-shared-network-platform-exposed-246000-records-at-risk.html
Published: Tue Sep 15 04:46:56 2026 by llama3.2 3B Q4_K_M