Japan’s Digital Agency confirmed that an unauthorized external party breached its shared Government Solution Service network, potentially exposing personal information belonging to approximately 246,000 government personnel and private-sector workers.
According to the agency, the incident stemmed from a vulnerability in equipment used for external network connections, allowing an outside attacker to access internal files beginning in late May. The Digital Agency detected the intrusion on June 25 after an account assigned to a maintenance and operations worker began pulling large volumes of data.
Investigators confirmed the breach on July 9, cutting off the compromised device’s external communications and suspending the compromised maintenance account.
Chief Cabinet Secretary Minoru Kihara said the government took the incident seriously because it occurred despite multilayered security measures and round-the-clock monitoring, according to The Japan Times.
Digital Minister Hisashi Matsumoto also addressed reporters, stating: “I offer my sincerest apologies. We take this matter extremely seriously and will spare no effort to prevent a recurrence.”
The agency confirmed that the incident did not affect information held in public-facing government services. Highly sensitive identifiers — including national My Number records, bank account details, and pension numbers — were also spared. However, the affected files contained roughly 236,000 names, 231,000 email addresses, 94,000 telephone numbers, and 1,000 physical addresses. The information concerned about 189,000 personnel across 23 government organizations, including the Imperial Household Agency and the Agriculture Ministry, as well as approximately 57,000 people associated with private companies and other organizations.
The breach illustrates a critical vulnerability inherent to unified public-sector IT modernization.
Following the telework surge triggered by the COVID-19 pandemic, Japan established the Government Solution Service in 2021 to tear down ministry data silos and streamline administrative operations under a modern zero-trust security model. Yet, by pooling over 150,000 workers onto a single shared infrastructure, the government created a high-value target where one compromise could affect multiple organizations.
Consolidating government systems can simplify maintenance, but it also increases the potential reach of a compromised external connection or privileged account.
Operational fallout and escalating threats
While the Digital Agency said it has detected no secondary misuse so far, the potentially exposed data presents a spear-phishing hazard. If attackers retained the information, verified work email addresses, telephone numbers, and organizational relationships could help them create convincing phishing and impersonation campaigns targeting government personnel.
The intrusion mirrors a broader surge in cyber threats nationwide. Japan logged 123 ransomware attacks in the first six months of 2026, marking the highest volume recorded in any half-year window since the National Police Agency began compiling figures.
For security leaders, the incident reinforces that zero-trust architecture still depends on continuous verification, rapid patching, and layered defenses. Organizations should promptly patch internet-facing equipment, limit the privileges assigned to contractor accounts, monitor unusual bulk downloads, and warn affected personnel about targeted phishing and impersonation attempts.
Read more: Recent AI-driven attacks, critical exploits, and major breaches show how weaknesses in internet-facing systems can expose organizations to wider security threats.





