NewsMacroJapan’s Digital Agency breach exposes data linked to 246,000 records

Japan’s Digital Agency breach exposes data linked to 246,000 records

Author: Cryptopolitan·

Key Takeaways

  • The breach affected government personnel and contractors across multiple ministries using the shared Government Solution Service.
  • Exposed data included names, email addresses, phone numbers and physical addresses, totaling approximately 246,000 record sets.
  • Investigators identified a vulnerable VPN device as the likely entry point and traced the intrusion to late May.
  • Japan’s Digital Agency said it had found no confirmed cases of misuse linked to the exposed information.
  • Analysts will watch for possible use of the leaked data in phishing, violent attacks or cryptocurrency-related crimes.
Japan’s Digital Agency breach exposes data linked to 246,000 records

Japan suffered another major cybersecurity breach on Friday, September 11, after attackers accessed the country’s Digital Agency and exposed approximately 246,000 personal data record sets.

The incident affected names, email addresses and phone numbers belonging to Japanese civil servants and contractors. The attacker entered a shared government network, according to the agency. The Digital Agency said the exposed information has not been linked to any confirmed cases of misuse, which can range from phishing campaigns to violent attacks.

What data was exposed?

The attackers accessed government email addresses and personal phone numbers connected to real names through the Government Solution Service (GSS), a shared work platform used by ministries and agencies across Japan. Because the platform is shared across government organizations, the exposed records were connected to multiple public-sector users rather than a single department.

The breach was smaller in scale than the My Number-related incident that affected ordinary citizens. By data category, the exposed information included 236,000 names, 231,000 email addresses, 94,000 phone numbers and 1,000 physical addresses.

How the attackers entered the network

The Digital Agency said it detected unusual activity on June 25, after an account belonging to a maintenance and operations contractor accessed a large number of files. Investigators determined that the intrusion had begun in late May.

Several weeks later, investigators identified a vulnerability in a VPN device as the likely entry point. The agency said it suspended the account and disconnected the compromised equipment from the external network on the same day it issued its July 9 update.

France’s DGFiP tax authority was also breached through a similar compromise involving an internal VPN, as Cryptopolitan previously reported.

Japan remains a frequent target

Japan ranks among the world’s ten most targeted countries, according to CloudSEK’s 2026 cybercrime report. The breach is notable because Japan established the Digital Agency in 2021 to modernize and secure government information technology.

In July, approximately 12.23 million email addresses and 7.61 million passwords were exposed in a confirmed breach involving KDDI.

Chinese hackers also breached Japan’s National Center of Incident Readiness and Strategy for Cybersecurity in a 2023 attack that was suspected to have gone undetected for months.

Potential risks for crypto holders

Leaked personal information can also be used in attacks targeting cryptocurrency holders. Telegram founder Pavel Durov highlighted a personal data leak involving a French government institution after 41 crypto-linked kidnapping incidents were reported in France during the first three and a half months of the year.

Chainalysis recorded more than $30 million stolen in violent attacks during the first half of 2026. That figure was on track to exceed the $58 million stolen in such attacks in 2025.

Analysts will monitor whether the 236,000 names and 231,000 email addresses exposed in Japan’s Digital Agency breach appear in future attacks or other misuse.