Find notable cyber news and cases, enriched with sources, timelines, and signals.

Japan’s Digital Agency hit by network compromise

Incident
First reported
Last updated
Happening score
H score 52
1 unique sources, 1 articles

Summary

Hide ▲

Japan’s Digital Agency disclosed an unauthorized-access breach that may have exposed about 246,000 record rows of government-employee personal information. The intrusion entered through a VPN device vulnerability in the Government Solution Service (GSS) environment. The agency suspended the compromised account, severed outside communication, and reported no confirmed misuse or government-service outage.

Related Happenings

GSS VPN device access security flaw

Vulnerability
H score54 First: 14.09.2026 23:36 Last: 14.09.2026 23:36 Sources 1

How related: The agency says that the attacker gained initial access by exploiting a vulnerability in a VPN device used by the Government Solution Service (GSS).

About this happening: Japan’s Digital Agency disclosed a VPN-device vulnerability in Government Solution Service (GSS) infrastructure that enabled initial access and unauthorized system...

KDDI email-system credential leak affecting Japanese ISPs

Data Leak
H score98 First: 24.06.2026 15:45 Last: 24.06.2026 15:45 Sources 1

About this happening: A KDDI email-system breach exposed customer credentials across six Japanese ISPs, putting up to 14.22 million email addresses and passwords at risk. The compromise was...

KDDI Corporation hit by network compromise

Incident
H score92 First: 24.06.2026 15:45 Last: 24.06.2026 15:45 Sources 1

About this happening: KDDI Corporation confirmed an email-system breach that exposed customer credentials across six Japanese ISPs, putting account access at risk. The intrusion was detecte...

Latest development: 08.07.2026 14:24

Attackers breached the KDDI email platform used by five Japanese ISPs on May 16 after exploiting a zero-day vulnerability in third-party software, exposing email addresses and passwords across the affected service providers.

Timeline

  1. 14.09.2026 23:36 1 articles · 2h ago

    Large-scale file access triggers investigation at Japan’s Digital Agency

    Detection Ioc Update

    Japan’s Digital Agency detected large-scale file access from the account of a maintenance and operations staff member and began an investigation into possible unauthorized access to government employee information.

    Show sources
  2. 14.09.2026 23:36 1 articles · 2h ago

    VPN vulnerability gives unauthorized access to GSS systems

    Exploitation Observed

    A third party was found to have used a vulnerability in a network-connected VPN device used by the Government Solution Service (GSS) to gain unauthorized access, and the agency suspended the compromised maintenance account and cut off outside communication from the affected equipment the same day.

    Show sources
  3. 15.07.2026 03:00 2 articles · 2mo ago

    Japan’s Digital Agency notifies privacy commission after personnel data exposure

    Victim Impact Update

    Japan’s Digital Agency notified Japan’s Personal Information Protection Commission and said the breach may have exposed about 246,000 record rows containing names, email addresses, telephone numbers, and physical addresses of government employees, public officials, and related parties; no confirmed misuse was detected and government services were not disrupted.

    Show sources