Q & A on "Possibility of Leakage of Personal Information of Employees, etc., through Unauthorized Access to Government Solution Services"
We will post a Q & A about this incident.
The investigation into this incident is still ongoing, and there are some matters that are withheld from disclosure due to security measures. In addition, the content may be updated depending on future investigations. Thank you for your understanding in advance.
- 1. Time series and detection process
- 2. Probable Causes
- 3. Scale and Number of Damages
- 4. Management system and responsibilities
- 5. Future Response
1. Time series and detection process
Q: How did this incident come about?
A: On June 25, 2026, we detected that a large number of files on a server were accessed using an account belonging to a maintenance operations person, and we initiated an investigation.
The investigation established that on July 9, a third party used a vulnerability in a network-connected device (VPN) to infiltrate the system and gain unauthorized access.
On the same day, the account of the person in charge of maintenance and operation was suspended, and external communications were cut off to prevent further unauthorized access.
At the initial stage of detection, the presence or absence of unauthorized access and the scope of the impact were not clear, and it took a considerable amount of time to analyze the intrusion route, identify information that may have been leaked, and identify those whose personal information may have been leaked.
As a result, the possibility of leakage of personal information was confirmed. At the stage where certain facts could be confirmed, we promptly made an announcement.
Q: Why did it take so long to announce the case after it was discovered?
A: In this case, immediately after we detected unauthorized access, we took measures to prevent the spread of damage, and with the cooperation of external specialized businesses, we are investigating the facts and confirming the content of information that may have been leaked.
At the initial stage of detection, it was not clear whether there was any unauthorized access or the scope of the impact. Therefore, it took a considerable amount of time to analyze the intrusion route, identify information that may have been leaked, and confirm the target of personal information that may have been leaked.
As a result, the possibility of leakage of personal information was confirmed. At the stage where certain facts could be confirmed, we promptly made an announcement.
2. Probable Causes
Q: Why did this happen? What is the cause?
A: In this case, a third party exploited vulnerabilities in VPN devices to gain unauthorized access, and as a result, we have confirmed that files containing personal information may have been leaked externally, and Digital Agency takes this matter seriously.
In light of this incident, Digital Agency is working to strengthen its management of vulnerabilities so that it can take prompt and proactive measures based on more substantial risks, taking into account the significance of governmental information systems.
Q: What are the vulnerabilities exploited in this incident?
A: The vulnerability exploited in this incident was medium (CVSS value * Medium level) in the vulnerability assessment that was initially announced.
We would like to refrain from answering the specific details of the vulnerability, as it could hinder future security efforts.
- *CVSS (common vulnerability scoring system): The CVSS is an international index that evaluates the risk and severity of vulnerabilities with scores ranging from 0.0 to 10.0.
Q: Was the vulnerability known and properly addressed?
A: The vulnerabilities in this incident were publicly disclosed before the attack was confirmed.
In Digital Agency, we addressed the vulnerabilities earlier than the general public.
As a result, the vulnerability was exploited before the security patch was applied, which we take very seriously.
In light of this incident, and in consideration of the importance of government information systems, we will work to strengthen our vulnerability management so that we can take more prompt and proactive measures based on substantial risks.
Q: Is the vulnerability gone?
A: At this point in time, in addition to applying the security patch, we have taken the necessary containment measures against the identified unauthorized access, including changing the authentication information of the relevant accounts and cutting off communication with the outside world. Since then, we have not confirmed any new unauthorized access or suspicious communication. We will continue to strengthen monitoring and strive to ensure safety.
3. Scale and Number of Damages
Q: What is the scale of the damage and the number of people?
A: The breakdown of approximately 246,000 cases of personal information that may have been leaked in this case is as follows.
- Information on the staff of the GSS user organizations and public officer (* including the staff of independent administrative institutions) who were involved in the work of the GSS user organizations: about 189,000
- Information on companies and individuals involved in the work of GSS user organizations: about 57000 people
The attributes of personal information that may have been leaked are listed in descending order.
- Names: about 236,000
- Mail address: About 231,000
- Telephone numbers: about 94000
- Address: about 1,000
And so on.
Q: What is personal information?
A: We have confirmed that the file that may have been leaked contains personal information such as names, email addresses, phone numbers, and addresses of employees.
To use the system, it is necessary to submit an application form for user registration. This form must contain information such as the name of the representative, the phone number used for work, and the address of the workplace. This information may have been leaked.
As a result, we have confirmed that many of the phone numbers and addresses are not personal, and most of them are registered as the locations of government buildings of various ministries and agencies and contact information used for official duties.
As a result of the investigation, we have confirmed that the potentially leaked information does not include My Number, financial institution account information, Pension Number, etc.
Q: Does it include the personal information of ordinary citizens?
A: It does not include personal information of ordinary citizens.
The personal data of citizens of countries other than public officer includes the names of employees and sole proprietors of companies involved in the work of ministries and agencies using the GSS, as well as those who participated in web conferences held by the relevant ministries and agencies, as well as email addresses and phone numbers used for work and the locations of business offices.
Q: 240,000 records were leaked? What do you mean by "possible"?
A: Regarding information for which traces of unauthorized access have been confirmed, we use the expression "there is a possibility" because we place top priority on protecting the people concerned, and we cover information including those for which the possibility of leakage cannot be denied.
Q: Was there any disruption to government operations using the GSS?
A: In response to this incident, we have cut off communication between the compromised device and the outside world, and there has been no hindrance to the government's business using GSS.
4. Management system and responsibilities
Q: How do you manage your VPN equipment?
A:VPN equipment is a part of the GSS system and is responsibly managed by Digital Agency. The system is such that manuals, etc. are prepared, and appropriate management is entrusted to employees, and in some cases, to external operators.
Q: Are there other systems or equipment that have had similar deficiencies?
A: The impact of this incident was limited to the system in question, and we have not confirmed any damage such as unauthorized access to other systems or information leakage.
Although we have not confirmed any incidents leading to similar damage as this incident, we will continue to inspect and monitor them and take necessary measures, as cyberattacks methods are becoming more advanced every day.
Q: How did you manage vulnerabilities?
A: In this system, we continuously collected and evaluated vulnerability information, checked vulnerability information and various warning information released by vendors regarding devices and software used in the system, assessed the impact, and took necessary measures.
On the other hand, in this incident, the vulnerability was exploited by an attacker, resulting in unauthorized access. We take this matter seriously and will re-examine the process from identifying vulnerability information to evaluating and implementing countermeasures, and will strengthen operations so that we can respond more quickly and reliably.
Q: Was GSS not safe with its Zero Trust Architecture?
A: We have adopted Zero Trust Architecture, but as a result, there was a possibility of illegal access and information leakage, which we take very seriously.
We would like to refrain from disclosing the details of the specific security measures taken by GSS and the details of the system configuration. Disclosing this would mean disclosing information on our systems and security measures, which would benefit attackers.
Based on the knowledge gained from this incident, we will work to further strengthen security.
5. Future Response
Q: What about dealing with subjects whose personal information may have been compromised?
A: First of all, we would like to apologize once again for causing great inconvenience and concern to those who are eligible for personal information that may have been leaked.
Digital Agency is currently conducting a detailed examination of personal data that may have been leaked, and we will contact you individually, starting with those whose contact information has been identified.
In addition, we will set up a dedicated contact point for inquiries and will respond carefully to consultations and questions from eligible people.
At this time, we have not confirmed any secondary damage, such as misuse of personal information, resulting from this incident. However, we will continue to monitor the situation and take necessary measures.
[Contact Information for Eligible Customers]
Group of Service for Ministries Administration GSS
- Toll Free Number: 0120-360-036
- Email address for dedicated inquiries: kojin-info _ atmark _ digital. go. jp
- *To prevent spam mail, " atmark " is displayed instead of "@". Please replace " atmark " with "@" (one byte) when sending e-mail.
Q: What kind of preventive measures and security enhancement measures will Digital Agency take?
A: In response to the occurrence of this incident, we will analyze the cause of the incident with the cooperation of external expert service providers. We will also strengthen vulnerability management and review the connection environment for external parties. At the same time, in addition to measures to prevent unauthorized intrusion, we will strengthen measures to minimize the impact of intrusion if it occurs. Furthermore, we will take necessary measures to prevent recurrence, such as by conducting constant reviews of these measures.
As for the details of the specific measures, I would like to refrain from answering because they are matters related to future system defense and security assurance, but Digital Agency will work to strengthen its security measures.