digital-agency-gss-2026 · Disclosed 2026-09-11
Digital Agency GSS: entry through an unpatched VPN
Unauthorized access used a known VPN vulnerability in a GSS maintenance environment. The patch was unapplied, with about 246,000 records potentially leaked.
Outcome: Confirmed breach
Entry path and evidence
Timeline
Incident disclosed. [s1]
Reported response
- Reported fact
The agency reported disabling maintenance access and communications, patching, and password changes.
[s1]Q&A:実施した対応
Evidence relevant to prevention
Patch available beforehand
Prioritize using exposure and maintenance privileges as well as CVSS, and retain evidence of applied fixes.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence.
VPN product and CVE are undisclosed; June 25 is anomaly detection, not an established intrusion start.
Sources
[s1] デジタル庁 · Primary source
GSSにおける不正アクセスについて(Q&A) ↗Published 2026-09-12 · Reviewed 2026-10-02