JAPAN’S Digital Agency has disclosed a data breach affecting approximately 240,000 people after attackers accessed files held by its Government Solution Service (GSS). The incident was discovered in late June, when the attackers used a maintenance and operations employee’s account. An investigation in July found that they had exploited a vulnerability in a VPN product, which the agency did not identify. The vulnerability had already been publicly disclosed before the attack was confirmed.
The agency said more than 246,000 records were compromised, including approximately 236,000 names, 1,000 addresses, 231,000 email addresses and 94,000 phone numbers. The affected people include users, public officials, administrative staff, and businesses and individuals working with GSS. The information had been submitted when applying to use the service. Most addresses and phone numbers were linked to workplaces, such as government buildings or offices. Individual identification numbers and financial account information were not affected.
After confirming the exploitation, the agency blocked external access to the affected server and suspended the employee account used in the attack. It said no other systems were compromised and that information belonging to the general public was not involved. The agency also said it would strengthen vulnerability management.