Skip to content
>_ITDITDWeb Security Platform

Security Guides

VPN Appliances Are the Biggest Way In — Remote Access Defense After Japan's Digital Agency Breach

Japan's Digital Agency disclosed that a VPN vulnerability let an attacker into its GSS government work environment, possibly exposing about 246,000 records. What is confirmed, and how to defend VPN appliances.

Published 2026-09-11 Updated 2026-09-11 Last verified 2026-09-11 12 min read

Who this is for: administrators of VPN and remote access equipment, and staff or contractors who may hear from Japan's Digital Agency. This article is based on public information — the agency's official announcement, National Police Agency statistics and reporting — and contains no attack techniques.

What happened (per the Digital Agency)

On 11 September 2026, Japan's Digital Agency announced that unauthorised access to the Government Solution Service (GSS) — a shared work environment it builds and operates for government ministries and agencies — may have exposed personal data about staff and others. Everything below comes from the agency's official announcement.

  1. 25 Jun 2026

    The agency detected a large volume of file access on servers using a maintenance operator's account and opened an investigation.
  2. 9 Jul 2026

    The investigation found that a third party had exploited a vulnerability in a network connection device (VPN) to get into the system. The same day, the account was suspended and the compromised device was cut off from outside communication.
  3. 11 Sep 2026

    The agency disclosed the personal data possibly exposed (about 246,000 records), said it would contact affected people individually, in turn, and set up a dedicated inquiry line.
~246,000
records possibly exposed in total — not a confirmed leak count
~189,000
GSS agency staff and public servants who worked on those operations
~57,000
contractors and individuals who worked on GSS agency operations
0
confirmed secondary misuse so far, per the agency
What may have been exposed (from the Digital Agency's announcement)
Who
Staff of ministries and agencies using GSS, and people who worked on their operations. The agency says it has "confirmed that personal information of the general public is not included"
Main items
Names ~236,000 / email addresses ~231,000 / phone numbers ~94,000 / postal addresses ~1,000, among others
Not included
My Number (national ID), bank account details, pension numbers and similar
Way in
A vulnerability in a network connection device (VPN). The product and the vulnerability identifier (CVE) have not been published
What triggered detection
Bulk access to files on servers using a maintenance operator's account
Secondary harm
"At this time, no secondary harm such as misuse of personal information related to this incident has been confirmed"
Remediation
"Reviewing how vulnerabilities are managed, improving how external connections are made, and so on"

How to read it: do not fill in what was not published

Three things have not been published: (1) the VPN product and which vulnerability; (2) when the intrusion began; (3) how the maintenance operator's account came to be used. The announcement sets two facts side by side — "got in through a VPN vulnerability" and "a maintenance operator's account was used to access a large number of files" — but does not describe what connects them. Posts naming a product are circulating on social media; this site does not publish what cannot be confirmed from primary sources. The confirmed facts alone are enough for defenders to learn from.

Why VPN appliances are the favourite target

This is not only about the Digital Agency. In National Police Agency statistics on ransomware in Japan, VPN devices have remained the largest entry point among cases where the route is known.

61 / 92
2025 cases with a known route where the entry was a VPN device (~66%)
19
same year: remote desktop (~21%)
2
same year: suspicious emails or attachments
293 / 485
VPN devices lead over five years as well (~60%)

Security awareness training tends to focus on "do not open suspicious email", but statistically the main battlefield is equipment placed facing the internet. The reason is structural.

Anyone on the internet can reach it

A VPN vulnerability is exploited

Inside, it acts as a legitimate account

Broad privileges reach a mass of files

Cut 1: patch speed

Known-exploited flaws first

Cut 2: narrow privileges

No maintenance account reads everything

Cut 3: detect bulk access

Where the agency noticed

A VPN appliance stands at the single point between outside and inside. Once it is breached, activity inside looks like legitimate use. There are three places to cut the chain.

Why VPN appliances get targeted

  • They sit where the internet can always reach them
  • Getting past one puts you inside the organisation
  • Activity inside looks like a legitimate user
  • The device's own OS is out of sight, so updates slip
  • The installer and the operator are often different parties, so nobody clearly owns patching

What the organisation decides

  • Knowing which devices, at which versions, you run
  • A deadline for how many days a known-exploited flaw may stay open
  • What one account can read once inside
  • A way to notice unusual volume or unusual hours of access
  • Whether to keep running the device at all

What to do today if you run VPN appliances

1

Inventory your VPN and remote access devices

Start with a list: model, firmware version, location and the person responsible for updates — not only VPN appliances but remote desktop gateways and firewall management interfaces too. Devices "handled by the vendor who installed them" are often the ones nobody knows the current state of. A device you do not know about is a device that does not get patched. The approach is laid out in the security inventory checklist.

2

Set a deadline for closing known-exploited vulnerabilities

Track vendor advisories and the catalogue of vulnerabilities known to be exploited (CISA KEV). A KEV entry is not "might be targeted someday" but "is being targeted now". For ordering by more than a severity score, see prioritising with CVSS, EPSS and KEV; for the working procedure, see the vulnerability remediation playbook.

3

Do not stop at the patch — rotate the credentials too

On a device that may have been exploited, a patch does nothing about credentials stolen before it was applied. Rotate the passwords, certificates and keys stored on or passed through that device, and look for accounts or configuration changes you do not recognise. "Closed the hole" and "removed the intruder" are two different jobs.

4

Do not give maintenance or contractor accounts the power to read everything

In the Digital Agency case, the account used for bulk file access was a maintenance operator's account. The announcement does not describe that account's privileges, but in general maintenance accounts tend to be given broad privileges for convenience. Limit them to what the job needs, enable them only when in use, restrict where they can connect from, and require multi-factor authentication — even if the entrance falls, an account that reaches little limits the damage. The pattern of maintenance and contractor paths being targeted also appears in the Osaka General Medical Center case (2022), where the investigation committee pointed to a contractor's remote-maintenance VPN device as the way in.

5

Make sure you would notice unusual volumes of access

What alerted the Digital Agency was a large volume of file access. It did not stop the intrusion, but detection is what let the agency scope it and cut it off. Alerts on file servers and cloud storage for bursts of downloads, bulk access at night, and use of dormant accounts can be set up without expensive products. For the underlying ideas, see indicators of attack (IoA) and EDR.

6

Decide whether to keep the device at all

If there is no one and no budget to keep up with updates, running the device is itself the risk. Alternatives — connection methods that do not expose an entrance to the internet, or services where the provider owns patching — are not cure-alls, but they are worth weighing because they make it clear who is responsible for updates.

If you may be contacted as staff or a contractor

Someone knowing your name and department is not proof they are genuine

The data possibly exposed is mostly names and email addresses — the combination used as a target list for impersonation email aimed at specific people (phishing). The Digital Agency asks people to watch for suspicious emails, calls and SMS messages impersonating the agency or related bodies, not to open links or attachments in unexpected messages, and never to enter credentials or card details.

If you want to check something, go to the Digital Agency's official website yourself rather than using a number or link from the message. Since about 94,000 phone numbers are also in scope, the same rule applies to calls that claim to be "verifying" something.

This site's view: what is worth copying here is that they noticed

Sakura Internet's investigation results, published days earlier, showed unauthorised access to its sales management system running for about three years (what to do when your web host is breached). By contrast, the Digital Agency incident was detected through an anomaly in volume — bulk file access. The intrusion itself was not prevented, so this is no clean success story. Still, since nobody can guard an entrance perfectly, the real difference is how quickly you notice once someone is in.

On the other hand, about two and a half months passed between detection (25 June) and disclosure (11 September), and the announcement does not describe that period. Scoping an incident often takes time, and that alone is not unusual. But from the affected person's side, it means learning months later that your contact details may have reached a third party. So rather than waiting to be contacted, it makes sense to be on guard against impersonation starting today.

Sources

The facts above come from the following public records. No speculation about the unpublished product name or intrusion details.

  • Digital Agency (Japan), "On the possible leak of personal information of staff and others due to unauthorised access to the Government Solution Service" (published 11 September 2026, Japanese) — digital.go.jp
  • National Police Agency (Japan), "The state of threats in cyberspace in 2025", statistics section on ransomware infection routes (of 92 valid responses, 61 VPN devices and 19 remote desktop; over five years, 293 of 485 were VPN devices; Japanese) — npa.go.jp
  • Reporting by INTERNET Watch, ITmedia NEWS and Jiji Press (11 September 2026), all based on the announcement above

Update log

2026-09-11: First version, based on the Digital Agency's 11 September announcement and the National Police Agency's 2025 statistics. Will be updated as further details are published.

FAQ

QWhat may have been exposed in the Digital Agency breach?
A

According to the Digital Agency's announcement of 11 September 2026, personal data about staff of the ministries and agencies that use the shared government work environment called the Government Solution Service (GSS), and about people who worked on those agencies' operations — about 246,000 records in total. Roughly 189,000 relate to agency staff and public servants, and roughly 57,000 to contractors and individuals. The items include about 236,000 names, 231,000 email addresses, 94,000 phone numbers and 1,000 postal addresses. The agency says My Number (national ID numbers), bank account details and pension numbers were not included, and that it has confirmed no personal data of the general public was involved.

QWhat was the cause?
A

The agency states that a third party exploited a vulnerability in a network connection device (VPN) to get into the system. What triggered detection was a large volume of file access on servers using a maintenance operator's account. Neither the VPN product nor the specific vulnerability (CVE) has been named. This site does not speculate about unpublished product names or intrusion details.

QHow do I find out whether I am affected?
A

The agency says it will identify affected people and contact them individually, in turn, and it has set up a dedicated inquiry line. If you want to check yourself, do not use links in any message you receive — go to the Digital Agency's official website directly and find the contact point there.

QWhat should affected people watch out for?
A

The agency asks people to be wary of suspicious emails, phone calls and SMS messages impersonating the agency or related bodies, not to open links or attachments in unexpected messages, and never to enter passwords, credentials or card details. The exposed data is mostly names and email addresses — exactly the combination used as a mailing list for targeted impersonation. A message from someone who knows your correct name and department is not, by that fact alone, genuine.

QWhat should an organisation that runs VPN appliances do first?
A

Build an inventory. List every VPN and remote access device you have, its model and firmware version, and who is responsible for updating it. Then track vendor advisories and the list of vulnerabilities known to be exploited in the wild (CISA KEV), and patch anything that matches first. On a device that may have been exploited, patching is not the end: rotate any credentials stored on or passed through it.