Japan government system hit by cyberattack; 246,000 personal records may have been leaked


TOKYO: The government’s common infrastructure network was the target of a cyberattack that started in May, digital minister Hisashi Matsumoto announced Friday. About 246,000 personal records of national civil servants and other personnel may have been leaked.

The analysis indicates that a third party hacked the system by exploiting a bypass of a virtual private network, or VPN.

The Digital Agency detected on June 25 that an account belonging to a maintenance and operations staff member had accessed a large number of files on a server. This kicked off their investigation and it was determined on July 9 that unauthorised access was occurring. On the same day, the agency suspended the account and blocked the affected devices from accessing anything outside the system.

The personal data that may have been leaked includes 189,000 records of employees at government agencies and independent administrative agencies that use the network, called the Government Solution Service (GSS). About 57,000 records of businesses and individuals involved in these agencies' operations may also have been leaked.

The possibly leaked data includes names, email addresses, phone numbers and addresses. Data related to My Number, the individually assigned identification number, financial institution account information and pension numbers were not leaked.

Although there are no confirmed cases of personal data misuse at this time, the agency is urging caution, as the information could be used for fraudulent purposes.

According to the agency, the GSS was first introduced in 2021, and as of the end of July, about 154,000 people across 23 organisations use it. The organisations include the Agriculture, Forestry and Fisheries Ministry, the Imperial Household Agency and the National Personnel Authority.

Previously, each ministry and agency maintained its own network. However, due to the widespread adoption of telework and such during the COVID-19 pandemic, efforts were made to establish a common network infrastructure. This contributed to work-style reforms for national civil servants and other personnel.

Although security improved with a zero-trust network—which treats all communications as potentially subject to cyberattacks—the agency could not prevent the breach.

At a press conference on Friday morning, Matsumoto said: “I offer my sincerest apologies. We take this matter extremely seriously and will spare no effort to prevent a recurrence.” The agency plans to review its vulnerability management methods and improve procedures for external connections. - Japan News

Follow us on our official WhatsApp channel for breaking news alerts and key updates!

Next In Aseanplus News

Over 30 per cent of unmarried people in Japan do not want children: survey
Indonesia presses Meta on child safety compliance after US ruling
Japan’s China-facing military build-up confronts labour, budget and political limits
China wife exposes husband’s US$1.5 million insurance-buying affair involving 180 hotel stays
True Fitness and True Yoga to shutter; customers report losses of more than $63,000
30 Malaysians detained over suspected online scam in Pontianak
Penang hotel introduces a ‘vintage’ way of touring George Town
Claims filed in Singapore relates to Eric Tan, Jho Low's associate, says 1MDB Asset Recovery Taskforce
Tributes flow in as Hong Kong mourns Tung Chee-hwa, pioneering first leader
Umno back in political spotlight after election gains, says division chief

Others Also Read