Find notable cyber news and cases, enriched with sources, timelines, and signals.

GSS VPN device access security flaw

Vulnerability
First reported
Last updated
Happening score
H score 54
1 unique sources, 1 articles

Summary

Hide ▲

Japan’s Digital Agency disclosed a VPN-device vulnerability in Government Solution Service (GSS) infrastructure that enabled initial access and unauthorized system access. The flaw was described as medium severity and not a zero-day, making it a concrete access-path weakness rather than a speculative issue. The breach may have exposed around 246,000 record rows tied to government-employee personal information.

Related Happenings

Japan’s Digital Agency hit by network compromise

Incident
H score52 First: 14.09.2026 23:36 Last: 14.09.2026 23:36 Sources 1

How related: The agency says that the attacker gained initial access by exploiting a vulnerability in a VPN device used by the Government Solution Service (GSS).

About this happening: Japan’s Digital Agency disclosed an unauthorized-access breach that may have exposed about 246,000 record rows of government-employee personal information. The intrusi...

Timeline

  1. 14.09.2026 23:36 1 articles · 2h ago

    Japan’s Digital Agency detects large-scale file access from a maintenance account

    Detection Ioc Update

    Japan’s Digital Agency detected large-scale file access from the account of a maintenance and operations staff member and started an investigation into possible unauthorized access to Government Solution Service (GSS) systems.

    Show sources
  2. 14.09.2026 23:36 2 articles · 2h ago

    VPN vulnerability enables unauthorized access to Government Solution Service systems

    Exploitation Observed

    Japan’s Digital Agency found that a third party used a vulnerability in a network-connected VPN device to gain access to the system and obtain unauthorized access; the issue was described as medium severity and not a zero-day, and the agency suspended the compromised maintenance account while cutting off external communication from the affected equipment.

    Show sources
  3. 14.09.2026 23:36 1 articles · 2h ago

    Exposure assessment finds personal data for government employees may have been exposed

    Victim Impact Update

    Japan’s Digital Agency said the breach may have exposed about 246,000 record rows containing government-employee personal information, including 236,000 names, 231,000 email addresses, 94,000 telephone numbers, and 1,000 physical addresses, while excluding the general public’s data, My Number identification numbers, bank-account details, and pension numbers.

    Show sources
  4. 14.09.2026 23:36 1 articles · 2h ago

    Digital Agency notifies Japan’s Personal Information Protection Commission

    Legal Policy Action Update

    Japan’s Digital Agency notified Japan’s Personal Information Protection Commission and said the delay in public disclosure stemmed from the work needed to trace the intrusion path, identify potentially affected information, and determine who was affected.

    Show sources