Breaches · 4h ago
Japan’s Digital Agency said a VPN flaw may have exposed about 246,000 rows of personal data tied to government employees. The disclosure is a breach, not a malware case: no actor is named, but the scale and the concentration of personnel details make it worth attention now.
When names, roles, and other personal details sit together in one exposed set, they become easy material for convincing impersonation. That can help attackers sound legitimate to help desks, payroll, HR, or colleagues without needing to break in again.
For government organizations that keep employee directories or personnel files for identity checks, the lasting risk is reuse: the leaked records can power spearphishing and official impersonation long after the original access is closed. The reporting does not yet settle how far the exposure reached beyond those records.
2 sources covering this story
240,000 Hit by Data Breach at Japan’s Digital Agency
Hackers exploited a vulnerability in a VPN product to steal the personal information of roughly 240,000 people.
Japan's Digital Agency says VPN flaw exposed 246,000 personnel records
Japan's Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees.
Part of the PlainSec briefing for 2026-09-15