Japan Digital Agency GSS VPN breach (2026): what was exposed and what to do

Updated Corrections

October 3, 2026

We publish these pages from public notices and reporting so you can understand what was exposed. Everything here is already public. Always confirm with the organization named in your notice.

Japan’s Digital Agency disclosed on September 11, 2026 that personal information in its Government Solution Service (GSS) may have leaked after unauthorized access. The agency says the information concerns government staff and people or businesses involved in their work, not the general public.

What the agency confirmed

Large-scale file access using a maintenance account was detected June 25. On July 9 investigators identified a VPN-device vulnerability as the entry point; the account was suspended and external communications from the compromised device were cut off.

The agency reports approximately 246,000 cases of personal information that may have leaked. That is not a verified count of unique people. The potential information includes names, email addresses, phone numbers and street addresses. Attribute counts overlap.

The agency says My Number national identifiers, financial-institution account information and pension numbers were not included. Its September 11 notice reported no confirmed secondary misuse and said affected individuals would be contacted individually.

Sources

What to do

  • If you receive an agency notice, keep it and follow the instructions applicable to you.
  • Verify unexpected contact using the official notice. Its inquiry channels are 0120-360-036 and kojin-info@digital.go.jp.
  • Be cautious about messages referencing a ministry, employer or contractor role. Do not provide passwords or payment-card details to someone who contacts you unexpectedly.
  • Do not infer that an unrelated Japanese resident or every government employee was affected from the headline alone.

Where Delist fits

Delist does not inspect GSS files or establish incident membership. A personal-data exposure scan is separate from the agency’s investigation and individual notifications.

This summary is compiled from public notices and reporting available when this page was last updated. Figures may change as investigations continue. Confirm your own exposure and any assistance offer with the organization named in your notice.

Inclusion is a record of a publicly reported incident, not an allegation of wrongdoing or negligence.

Does 246,000 mean that many unique Japanese residents were affected?

No. The Digital Agency describes approximately 246,000 cases of personal information that may have leaked, with overlapping attributes. It is not a unique-person count. The agency says the potentially leaked information concerns government work and does not include the general public.

Frequently asked questions

Were My Number identifiers, bank accounts or pension numbers included?

The agency’s September 11 notice says those categories were not included in the potentially leaked information.

Can Delist check whether my information was in GSS?

No. Delist does not inspect GSS files or determine incident membership. Use the agency’s individual notification and official inquiry channels.

What to do after a breach

A free Delist scan checks open-web exposure we support: people-search sites, public records, data brokers, and breach-source signals. Signals are not live listings, and this is not removing you from a dump, a DMV database, or a vendor's private ID store.

More breaches

Free personal data exposure scan

We search the open web for your personal data and show what’s exposed. The scan is free. Removal and monitoring require a paid plan.