Japan ‘s Digital Agency disclosed that attackers exploited a vulnerability in a VPN device to access its Government Solution Service (GSS), potentially leaking personal information belonging to approximately 246,000 government employees, public officials, and contractors. The breach was detected on June 25 and confirmed as a VPN exploitation on July 9, meaning the public disclosure came 78 days after the initial detection and 63 days after the intrusion method was identified.
“It has come to our attention that, due to unauthorized external access, some files containing personal information handled on the Government Solution Service (GSS), operated by the Digital Agency, may have been leaked to an external party.” reads the advisory. “We have confirmed that the personal information that may have been leaked pertains to employees of various ministries and agencies that use GSS (hereinafter referred to as “GSS user organizations”) and those involved in their work, and does not include personal information of the general public.”
GSS connects 23 Japanese ministries and agencies through shared IT infrastructure. A breach of this platform could potentially affect many government organizations at once.
by Security Affairs – Non-Zero-Day VPN Flaw Left Japan ‘s Government Shared Network Platform Exposed: 246,000 Records at Risk



