Japan's Digital Agency Reports Data Breach via VPN Flaw Exposing Personnel Records
Approximately 246,000 government employee records potentially compromised due to a VPN vulnerability

Key Takeaways
- Japan's Digital Agency discovered a data breach exposing approximately 246,000 government employee records.
- A VPN flaw served as the initial access vector for unauthorized personnel database access.
- The vulnerability has been remediated and access controls are under review.
- The exact exploitation method, VPN product, and data exfiltration status remain unconfirmed and under investigation.
Related Security News

Times Car Confirms Data Breach Affecting 6.6 Million User Accounts
Times Car, a Japanese car-sharing service, has confirmed a data breach compromising approximately 6.6 million user accounts. The incident was disclosed late last week, with the exact attack vector and nature of exposed personal information yet to be fully specified. Authorities and the company are reportedly investigating the breach.

French Tax Administration Data Breach Exposed Hundreds of Thousands of Records via Stolen Staff Credentials
An unauthorized access incident at France's Direction Générale des Finances Publiques (DGPP) compromised tax data belonging to hundreds of thousands of taxpayers and businesses between June and July 2026. According to a report published by France's national cybersecurity agency ANSSI on 29 September 2026, the attacker used stolen staff passwords to gain entry. The agency stated the attack was 'not sophisticated' and went undetected for seven weeks due to weak security controls. ANSSI noted that neither the tax administration nor the agency itself observed data exfiltration, though the breach resulted in unauthorized access to sensitive fiscal information.



