Japan Digital Agency Data Breach Linked to VPN Vulnerability

Japan Digital Agency Data Breach Linked to VPN Vulnerability
Government Solution Service (GSS) of Japan's Digital Agency was compromised by a vulnerability in a VPN device, resulting in unauthorized access to the shared government platform through an exploit of a vulnerability in the VPN device. In this incident, 246,000 records containing information regarding employees, public officials, contractors, and other individuals connected to organizations using the service may have been exposed. Upon discovering unusually large-scale access to files on a server through an account belonging to a maintenance and operations staff member on June 25, the agency first detected the breach. Following an investigation, the agency determined that the account activity was linked to an unauthorized access to a network-connected VPN device. By July 9, the agency determined that an external party had accessed the system by exploiting a vulnerability in the VPN equipment. Immediately after the incident, the maintenance account was suspended, and communication between the equipment and external networks was restricted to prevent further access. The investigation, conducted with the assistance of an external security company, revealed that some files that contained personal information could have been transferred outside the system. The VPN product used and the specific vulnerability that was exploited have not been disclosed by the agency. Through shared IT infrastructure, 23 Japanese ministries and government agencies are served by the affected GSS environment, which can have a greater impact on the incident. The exposed information consists of approximately 236,000 names, 231,000 e-mail addresses, 94,000 telephone numbers, and 1,000 physical addresses. The records relate to personnel and officials who work with GSS user organizations, as well as businesses and individuals who support those organizations. Data containing information belonging to the general public was not included in the affected data, according to the agency. Additionally, the compromised dataset is lacking My Number identification numbers, bank account information, or pension number information. Despite the fact that no confirmed cases of misuse have been identified, the exposed contact information could still be used for impersonation, phishing, or other forms of social engineering. VPN exposures were categorized as medium severity and were not zero-day vulnerabilities; however, the agency has failed to provide details regarding when the vulnerability was fixed or why the device was still exposed at the time of the intrusion. Known VPN Flaw Left UnpatchedDue to the fact that the Digital Agency was already aware of a VPN flaw when the breach occurred, but had not applied the required patch, the incident raises concerns about vulnerability management. According to the agency, the vulnerability has a medium severity and has been confirmed as not a zero-day, indicating that attackers exploited a known vulnerability rather than a newly discovered vulnerability. The information accessed is approximately 246,000 records. Over 189,000 of these people are government employees, public officials, or other personnel working for GSS-related organizations, while approximately 57,000 are private companies and individuals involved in government-related activities. A total of 236,000 names, 231,000 emails, 94,000 telephone numbers, and 1,000 physical addresses were included in the data. In addition, duplicate entries may be present in the data. More sensitive identifiers are not included in the dataset, such as My Number information, bank account details, and pension information.Investigation Finds No Confirmed MisuseThe Digital Agency has not received any confirmations of misuse of the exposed information, however, the combination of names and contact information could facilitate targeted phishing or impersonation attempts against affected employees. Messages or phone calls from individuals pretending to represent the government have been warned by the agency, and official personnel will not contact affected parties via email or telephone for passwords or payment information. Japan's Personal Information Protection Commission was made aware of this incident on July 15. During the investigation, the agency determined that potentially affected information was likely to be identified and the individuals and organizations involved required a considerable amount of time, which contributed to the delay in public disclosure. Digital Agency officials indicated the impact was limited to the affected GSS environment with no evidence of other government systems being compromised or disrupted. As part of its effort to strengthen vulnerability management and review how external connections to the system are handled, the agency is also expected to provide direct notifications to the affected individuals. To prevent unauthorized access to sensitive government information and limit unauthorized access, VPN patches should be implemented on time, strict access controls should be implemented, continuous monitoring should occur, and rapid isolation should be instituted.

Take Your Experience to the Next Level

New

Download our mobile app for a faster and better experience.

Comments

0
U

Join the discussion

Sign in to leave a comment

0:000:00