Japan Digital Agency Breach Exposes 246K Staff Records
Japan's Digital Agency disclosed a VPN breach affecting roughly 246,000 rows of government employee personal information. The specific CVE and VPN vendor have not been named.

Japan’s Digital Agency confirmed September 14 that a flaw in a VPN appliance used in the agency’s network exposed approximately 246,000 rows of personal information belonging to government employees, BleepingComputer reported. The specific VPN vendor and CVE have not been publicly identified in the agency’s initial disclosure.
What’s known
The agency described the exposed data as record rows containing personal information of government personnel. What specific fields, names, ID numbers, contact details, or HR data, were included has not been confirmed in initial reporting. A row count of 246,000 in a government personnel system is substantial: that is not a leak of a single department’s records.
The flaw was in a VPN appliance at the network perimeter. VPN appliances sit at the boundary between the public internet and internal networks, and flaws in them routinely allow unauthenticated or pre-authentication access to data that should require credentials.
Not an isolated pattern
Japan has had a difficult stretch on this front. KDDI suffered a breach in July through a zero-day in a third-party component that exposed data for roughly 12 million customer accounts. That was a telecommunications provider. This one is a government agency handling civil service personnel records directly.
VPN-based perimeter compromise is not a Japan-specific problem. Two days ago, the Dutch NCSC issued a warning that exploitation of two critical Check Point VPN flaws was imminent, telling organizations that had not yet patched CVE-2026-85102 and CVE-2026-85103 to treat the situation as urgent. The Vietnam APIS incident this month put 220 million traveler records at risk through government infrastructure. The same vector, perimeter appliances that are harder to update than software endpoints, keeps showing up.
What still needs answering
The agency has not confirmed whether this was active exploitation by an attacker or passive exposure through a misconfiguration. That distinction matters. Active exploitation means an actor had persistent access to agency systems for some window of time. Misconfiguration means data may have been accessible without necessarily being exfiltrated. The initial disclosure does not settle that question.
Whether individual notifications to affected employees are planned, and whether the scope of 246,000 rows reflects unique individuals or includes duplicate records across time periods, are details that should come in a follow-up. Until then, what’s clear is that a government agency’s personnel data was reachable from outside the network because a VPN appliance had an unpatched flaw. That is the part that should have been fixed before the question became academic.
Found this useful? Share it.


