← Incident database

digital-agency-gss-2026 · Disclosed 2026-09-11

Digital Agency GSS: entry through an unpatched VPN

Unauthorized access used a known VPN vulnerability in a GSS maintenance environment. The patch was unapplied, with about 246,000 records potentially leaked.

Known vulnerabilityCredentials

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    A previously disclosed VPN vulnerability remained unpatched; its published severity was Medium.

    [s1]Q&A:原因と脆弱性の対応
  • Reported fact

    About 246,000 records are potentially exposed, not a confirmed exfiltration count.

    [s1]Q&A:流出の可能性

Timeline

  1. Incident disclosed. [s1]

Reported response

  • Reported fact

    The agency reported disabling maintenance access and communications, patching, and password changes.

    [s1]Q&A:実施した対応

Evidence relevant to prevention

Patch available beforehand

Prioritize using exposure and maintenance privileges as well as CVSS, and retain evidence of applied fixes.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence.

VPN product and CVE are undisclosed; June 25 is anomaly detection, not an established intrusion start.

Sources

  1. [s1] デジタル庁 · Primary source

    GSSにおける不正アクセスについて(Q&A) ↗

    Published 2026-09-12 · Reviewed 2026-10-02