Japan’s Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees.
The agency says that the attacker gained initial access by exploiting a vulnerability in a VPN device used by the Government Solution Service (GSS).
An investigation started on June 25, after the agency detected a large-scale file access from the account of a maintenance and operations staff member.
“On July 9th, it was discovered that a third party had used a vulnerability in a network-connected device (VPN) to gain access to the system and gain unauthorized access,” reads the announcement.
“On the same day, we suspended the account of the maintenance and operations personnel in question, cut off communication between the compromised equipment and the outside world, and prevented further unauthorized access.”
It is unclear what VPN product was affected or the vulnerability exploited in the breach. However, the Japanese agency said in a separate Q&A that the issue had a medium severity rating and was not a zero-day.
The investigation revealed that the following data may have been exposed:
236,000 names
231,000 email addresses
94,000 telephone numbers
... continue reading