Japan’s Digital Agency has disclosed a cyberattack on a government network that may have exposed personal information belonging to approximately 246,000 public servants, contractors and other people involved in government work.
Summary
- Japan’s Digital Agency said roughly 246,000 personal records may have leaked after an attacker exploited a VPN vulnerability.
- The affected data included around 236,000 names, 231,000 email addresses and 94,000 phone numbers belonging mainly to public servants and government contractors.
- Officials detected large scale file access through a maintenance account on June 25 and confirmed the unauthorized intrusion on July 9.
- The agency said no misuse of the potentially exposed information has been confirmed and My Number IDs, bank details and pension numbers were not affected.
The Digital Agency said on Sept. 11 that an investigation into its Government Solution Service, or GSS, found that an outside attacker exploited a vulnerability in a virtual private network device and gained unauthorized access to files containing personal data.
The agency first detected unusual activity on June 25, when a maintenance and operations account was used to access a large number of files stored on its servers. An investigation later established on July 9 that a third party had entered the system through the VPN vulnerability.
Officials disabled the affected maintenance account that day and blocked communications between the compromised network equipment and external systems to prevent further unauthorized access. A subsequent investigation carried out with outside security specialists found that some files may have been taken from the network.
Japan data breach may have exposed 246,000 records
The potentially compromised information belongs to employees of government ministries and agencies using GSS, public servants who worked with those organizations, and businesses and individuals involved in their operations.
Around 189,000 records concern employees of GSS member organizations and other public servants involved in their work, including employees of incorporated administrative agencies. Another roughly 57,000 records relate to businesses and individuals that worked with GSS organizations.
The affected files contained approximately 236,000 names and 231,000 email addresses. Roughly 94,000 phone numbers and about 1,000 addresses were potentially exposed, with some records containing more than one type of personal information.
Japan’s Digital Agency said the affected data did not contain My Number identification numbers, bank account details or pension numbers. It has confirmed that the personal information of members of the general public was not included in the potentially leaked files.
The agency warned that exposed contact details could potentially be used for impersonation or phishing attempts. It advised affected people not to open unexpected links or attachments or provide passwords, authentication information and credit card details in response to suspicious emails, calls or text messages claiming to come from government bodies.
VPN vulnerability gave attacker access to government systems
The intrusion involved a vulnerability in network equipment used for VPN access, while the large-scale file activity was carried out through an account belonging to maintenance and operations personnel.
The Digital Agency has not identified the attacker publicly or disclosed whether the intrusion was financially motivated. Its statement did not attribute the incident to a ransomware group, state-backed actor or other known hacking organization.
Following the investigation, the agency said it would review how vulnerabilities are managed and improve methods used for external connections to its systems.
The incident emerged during a period of elevated cybercrime activity in Japan. National Police Agency figures cited in local reporting showed the country recorded 123 ransomware attacks during the first half of 2026, the highest total for any six-month period since authorities began tracking the figure.
Security incidents involving compromised access and infrastructure have remained a concern outside government systems as well. A July crypto security report previously covered by crypto.news found that 212 verified crypto incidents caused $1.1 billion in losses during the first half of 2026, with 74% of stolen funds linked to operational security failures instead of exploited smart contract code.
A separate CoinGecko security study published in August calculated that crypto platforms lost $3.63 billion across 245 documented incidents between January 2025 and July 2026. The 10 largest attacks accounted for more than 72.5% of the total amount stolen during that period.
Japan has faced major crypto-linked cyberattacks
Japan has previously dealt with large cyber thefts targeting its cryptocurrency sector, including the attack on DMM Bitcoin that ultimately forced the exchange to wind down its operations.
The DMM Bitcoin breach resulted in the theft of more than 4,500 Bitcoin worth roughly $307 million at the time. Japanese authorities and the FBI later connected the operation to TraderTraitor, a North Korean-linked group associated with other cryptocurrency thefts.
Investigators found that the DMM Bitcoin operation began through social engineering targeting an employee at Ginco, a Japanese cryptocurrency wallet software company that provided services to the exchange. An attacker posing as a recruiter sent the employee a malicious Python script during what appeared to be a pre-employment test.
Access obtained through Ginco was later used to manipulate a legitimate DMM Bitcoin transaction request, according to authorities. The stolen Bitcoin was subsequently traced to wallets controlled by the attackers.
North Korean-linked groups have continued targeting cryptocurrency infrastructure outside Japan. Bybit said in August that its security systems blocked more than 30,000 suspicious withdrawals during the first half of 2026, preventing more than $700 million in potential user losses after the exchange suffered a $1.46 billion theft in February 2025.
The exchange said it had expanded continuous onchain monitoring following the attack, while its security teams processed more than 100,000 alerts with AI assistance during the first half of this year. Bybit’s monitoring systems identified 10 security incidents affecting listed token projects during the period without losses to the exchange.
Other recent breaches have centered on personal information rather than direct theft of digital assets. Israeli crypto broker Bits of Gold began investigating a customer data breach in August after unauthorized access to a third-party system potentially exposed names, identification numbers, email addresses, phone numbers, IP addresses and some banking information.
Bits of Gold said cryptocurrency, customer funds, passwords, identification document scans and full payment card details were not compromised in that incident. The company traced the exposure to third-party software affected by a larger breach and said it began investigating after receiving information about the incident.






