Possibility of Leakage of Personal Information of Employees, etc. by Unauthorized Access to Government Solution Services
- Published:
Recently, it has become clear that in the Government Solution Service (hereinafter referred to as "GSS") operated by Digital Agency, there is a possibility that some of the files containing personal information handled on GSS may have been leaked to external parties due to unauthorized external access.
We have confirmed that the personal information that may have been leaked is related to employees of the government agencies that use the GSS (hereinafter referred to as "GSS Utilizing Agencies") and those who were involved in the work, but does not include the personal information of the general public.
We are deeply sorry for causing so much trouble and concern to all concerned.
1. Outline of the case
On June 25, 2026, we detected that a large number of files on a server were accessed using an account belonging to a maintenance and operation person, and launched an investigation. On July 9, it was discovered that a third party had breached the system by exploiting a vulnerability in a network connection device (VPN) and had been performing unauthorized access. On the same day, we suspended the account of the maintenance and operation person in question and cut off external communications with the compromised device to prevent further unauthorized access.
As a result of investigating the incident with the cooperation of an external specialist, we have confirmed that there is a possibility that personal information has been leaked to an external party.
![The outline of the incident. At the top is the title "Occurrence of incidents that may lead to leakage of personal data due to illegal access to GSS R8.9.11 Digital Agency". In the middle of the title [Outline of the Incident], three points are described. (Point 1) On June 25, 2026, the account of the person in charge of maintenance and operation was used to access a large number of files on the server, which was detected, and the communication between the compromised devices and the outside world was cut off, which was approximately 246,000 cases. (Point 2) In the conceptual diagram on the left of the bottom, as a result of the investigation conducted with the cooperation of an external specialized business operator, it was confirmed that there was a possibility that personal data had been leaked to the outside. Next, as [Personal information that may have been leaked], three points are described (Point 1). The account of the person in charge of maintenance and operation was used to access a large number of files on the server, which was detected, and the investigation was started. (Point 2) On the right side of the bottom, it is written that [Security measures in response to the incident], major initial measures [1] Application of a VPN patch, [2] Suspension of the account, [3] Cut off communication with the outside, etc. As measures to prevent recurrence, it is written that [1] Review of vulnerability management method, [2] Improvement of connection method from the outside, etc. public officer Pension Number 189,000 57000](/assets/contents/node/information/field_ref_images/a461911b-badb-4cf7-b2ad-825b4fb6b41e/91af3fee/20260911_image.png)
2. Personal information that may have been leaked
We confirmed that the potentially leaked files include personal information such as names, email addresses, phone numbers, and street addresses. There are approximately 246,000 cases of personal information that may have been leaked.
The personal data that may have been leaked includes the employees of the GSS user organizations, public officer and other organizations that were involved in the work of the GSS user organizations, and businesses and individuals that were involved in the work of the GSS user organizations.
We have confirmed that the personal data that may have been leaked does not include My Number, financial institution account information, Pension Number, etc.
The breakdown of personal information that may have been leaked is as follows.
- Information from staff of GSS user organizations and public officer * involved in the work of GSS user organizations: about 189,000
- *Including employees of independent administrative institutions
- Information on business operators and individuals involved in the work of GSS user organizations: about 57000 cases
The attributes of personal information that may have been leaked are as follows. (There are duplicates.)
- Names: about 236,000
- Mail address: About 231,000
- Telephone numbers: about 94000
- Address: Approx. 1,000
3. Response to Eligible Persons
Digital Agency will identify the individuals whose personal data may have been leaked and will contact them individually in sequence.
At this time, we have not confirmed any secondary damage such as misuse of personal information related to this incident.
Personal data that may have been leaked may be abused for fraudulent e-mails, phishing e-mails, etc. Please be careful of suspicious e-mails, phone calls, SMSs, etc. pretending to be from Digital Agency or related organizations. Please do not open links or attachments included in communications you are not aware of, or enter credentials such as passwords or personal details such as credit card information. Also, Digital Agency will never ask for credentials such as passwords or personal details such as credit card information by e-mail or phone.
If you have any questions about this matter, please contact [Contact Information for Eligible Customers] below [Contact for inquiries of eligible persons].
4. Future Initiatives
In response to this incident, Digital Agency will continue to strengthen its security measures, such as reviewing its vulnerability-management methods and improving external connection methods, and will work to prevent recurrence.
5. Contact Information
[Contact Information for Eligible Customers]
Group of Service for Ministries Administration GSS
- Toll Free Number: 0120-360-036
- Email address for dedicated inquiries: kojin-info _ atmark _ digital. go. jp
- *To prevent spam mail, "@" is displayed as "
_ atmark _". When you send mail, please replace "_ atmark _" with "@" (one byte).
- *To prevent spam mail, "@" is displayed as "
[Contact information for press inquiries, etc.]
Please contact the following for inquiries from the media regarding this matter.
Group of Service for Ministries Administration GSS
- TEL: 03 6866 0151