Back to news

Japan's Digital Agency GSS Hacked, Potential Leak of Information for 246,000 People

Japan's Digital Agency disclosed that its Government Solutions Service (GSS) network was accessed without authorization, potentially leaking personal information of approximately 246,000 public officials and related personnel.

On June 25, the system detected unauthorized access to a large number of files on the server using an operations maintenance account. On July 9, it was confirmed that a third party exploited a VPN device vulnerability to infiltrate from outside. On the same day, the account was disabled, and communication between the compromised device and the outside was cut off. Subsequently, with the assistance of external professionals, it was confirmed that files containing personal information may have been leaked. Signs of the intrusion can be traced back to late May.

The potentially leaked records amount to approximately 246,000: about 189,000 employees of institutions using GSS and public officials involved in its operations (including employees of independent administrative agencies); about 57,000 business operators and individuals involved in related operations. The fields mainly include approximately 236,000 names, 231,000 email addresses, and 94,000 phone numbers, with about 1,000 addresses. The Digital Agency stated that personal identification numbers (My Number), bank account numbers, and pension numbers were not included, and currently, no direct related theft or secondary damage has been confirmed, but there is a warning about phishing and impersonation email risks, and they will notify the affected individuals one by one using the contact information they have.

GSS is a government-shared computer and communication platform established in 2021 for use by various ministries and agencies; it is publicly stated that about 23 institutions and 154,000 people are currently using it. Digital Minister Matsumoto Sho, at a press conference after the cabinet meeting, stated that the situation is extremely serious and will review vulnerability management, improve external access, and strengthen security. He admitted that the known VPN vulnerability was exploited, and the agency is currently prioritizing repairs based on urgency; from discovery to public disclosure took about two and a half months, citing the time needed for investigation, scope determination, and path analysis. The agency stated that patches and other measures have been implemented, and the possibility of further damage is very low, while also admitting that even with a zero-trust approach, there may still be vulnerabilities.

Product models, CVE numbers, and the identity of the attackers have not been disclosed. The affected parties include employees of ministries and agencies using GSS, related public officials, as well as contractors and individuals, representing data at the government office network communication level, rather than the core financial payment database.

In market mechanisms, this is not a trading incident but a discount on sovereign network trust. Buyers and beneficiaries are contractors who will undertake government security renovations, zero-trust reinforcement, VPN replacements, and emergency audits; the pressured party is the narrative of the "government common platform" led by the Digital Agency, as well as various ministries and agencies relying on the same remote maintenance entry. Funding will shift from routine IT operations to post-incident patching, notification costs, and increased security budgets. The high frequency of ransomware activity in Japan in the first half of the year places this leak within the same supply curve of "known vulnerability windows being industrially exploited": attackers sell the time difference for access, while the government pays for disclosure delays and patch queues.

Supplementary structure: GSS was originally intended to consolidate the decentralized networks of ministries into a controllable base; maintenance accounts and VPN edge devices became single points of failure. Known vulnerabilities had not yet been patched, which was enough to turn a user directory of 150,000 into a downloadable file package. From the alert on June 25 to the public disclosure on September 11, the gap itself could also be utilized by adversaries for pricing.

Source: Public Information

ABAB AI Insight

One of the main projects established by Japan's Digital Agency in 2021 is GSS: to replace the disparate remote access of various ministries with a unified terminal and network. Matsumoto Sho is tasked with advancing both digitalization and security reforms, but the management rhythm of "known high-risk vulnerabilities waiting to be patched" was outpaced by adversaries. This is not a new zero-day legend, but rather a case where patch management cannot keep up with scanners. Similar paths have repeatedly appeared in Japan's public sector—municipalities, hospitals, and large enterprises' VPNs and remote maintenance ports have repeatedly become entry points for ransomware and data exfiltration.

The direction of capital and resource mobilization will shift from "unified platform construction costs" to "edge device replacement + account permission reduction + external audits." The government will not discontinue GSS due to a single directory-level leak, but will invest budget into patch automation, privileged account control, and the implementation of zero trust. Contractors and security vendors will benefit from mandatory procurement following this incident; the Digital Agency will pay the price of political trust and accountability for the two and a half months of disclosure delay. The attackers, on the other hand, follow a standardized exploitation chain: scanning VPNs, leveraging maintenance accounts, and bulk file transfers; even if the data does not contain bank account numbers, names, email addresses, and phone numbers can still be resold for phishing and supply chain infiltration.

Comparable responses can be seen in U.S. federal agencies following SolarWinds and MOVEit, as well as the successive VPN edge device breaches in the public sectors of the UK and Australia. The industry phase belongs to remedial expansion following control failures: the platform has already been rolled out to 23 institutions and over 150,000 people, yet the security model still treats "maintenance accounts + VPN" as a trusted boundary. Zero trust is written in the architectural documentation, but operational habits remain stuck in the bastion host era.

Structural judgments indicate that regulatory changes lag behind the industrialization of attacks. The mechanism is: the semi-annual high of ransomware in national statistics indicates that the capacity to exploit known vulnerabilities has already been scaled; the government network's disclosure and patch queues operate on administrative cycles, while attacks proceed via automated scanning. Those who patch first pay less, while those who expand the shared platform but leave edge devices outdated provide adversaries with a window to download the national public servant directory.

Source

·ABAB News
·
9 min read
·16 hrs ago
分享: