VPN breach exposed 246,000 Japanese government personnel records
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Tuesday, September 15th, 2026.
Government employees face increased impersonation and phishing risk after a V P N-related breach at Japan’s Digital Agency. Around two hundred forty six thousand record rows containing personal information may have been exposed after an attacker exploited a known, medium-severity V P N issue and accessed a maintenance and operations account. The investigation began when the agency detected large-scale file access on June 25th. It isolated the affected account and device on July 9th. No government service outage or confirmed misuse of the information has been reported. Those potentially affected include government employees, public officials, and associated businesses and individuals using the Government Solution Service. The exposed information didn’t include records belonging to the general public, My Number identifiers, bank details, or pension numbers. Leaders should note that a medium-severity edge issue can still produce large data consequences when it’s paired with a privileged account. Defenders should monitor maintenance identities, patch network appliances, and notify affected people through verified channels. Review every privileged maintenance account linked to remote-access appliances, and investigate unusual bulk file activity.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.