한국어

Illegal Access to Japan’s Digital Agency (デジタル庁) Government Network, Potential Leakage of 24万 Personal Information Records

Japan’s Digital Agency announced on 11 that illegal access to the government’s common network had been confirmed.

In the process, the possibility was raised that approximately 24万 records of personal information belonging to government ministry employees and people involved in related work may have been leaked.

It is necessary to distinguish between the scope that has been confirmed and the scope that has not yet come to light.

3-Line Summary
1. The possibility of a personal information leak has emerged from the government network
2. The affected data consists of approximately 24万 records, including employee information
3. Whether the information was misused has not yet been confirmed

Names, Contact Information, and Addresses May Be Among the Affected Data

According to a report by the Asahi Shimbun, Japan’s Digital Agency announced on 11 that there had been illegal access to the Government Solution Service, a core network system provided to each government ministry. The information that may have been leaked includes the names, email addresses, telephone numbers, and addresses of government employees and others.

The scale of the affected data identified by the Digital Agency is approximately 24万 records. Information belonging to ministry employees and independent administrative agency personnel who use the network totaled 18만9천 records, while information belonging to contractors and others involved in the work of these institutions totaled 5만7천 records. NHK also reported, through a press conference by the Digital Agency minister, that more than 24万 records of personal information belonging to ministry employees and others had been leaked.

However, the Digital Agency explained that My Number, financial institution account information, and pension numbers were not included. The fact that the possibility of a personal information leak was confirmed and what information was included must be viewed as separate issues within the same matter. The items identified in this announcement concern identity, contact information, and addresses, and there is no basis to conclude that other personal information was leaked together with the items the government said were excluded.

Intrusion in Late May, Detection of Access to Large Numbers of Files in June

According to the Digital Agency’s explanation, the intrusion in question is understood to have begun around the second half of May. An investigation found that a third party entered the system by exploiting a vulnerability in VPN equipment used to access the organization’s internal network. A VPN is equipment or an access method used to connect securely to an organization’s internal network from outside.

The Digital Agency said it began an investigation after detecting traces of access to many files on a server from the account of personnel responsible for maintaining and operating the network in June. It subsequently took measures to suspend that personnel account. This describes the Digital Agency’s announcement regarding the intrusion route and response measures; it does not mean that the agency knows how the leaked information was actually used.

The Digital Agency said that no misuse of the information had been confirmed to date. However, this is an announcement that no cases of misuse had been discovered, not a conclusion that none of the information identified as potentially leaked had gone outside the organization at all. The names of the ministries potentially affected by the leak have also not been disclosed.

Problems with a Common Work Environment Used by 23 Institutions

This network was introduced beginning in 2021 and has been used by 23 institutions, including the Ministry of Agriculture, Forestry and Fisheries and the Cabinet Office, as well as 15만4천 people. Its purpose was to create a common government network environment, making remote work easier while improving productivity and security functions.

For that reason, this matter covers a broader scope than an individual service failure at a single institution. It involves an access problem occurring in a work infrastructure shared by multiple ministries and related institutions. Reports indicated that the number of potentially leaked records and the number of users differ because the populations being counted are different. The former refers to the number of personal information records that may have been leaked, while the latter refers to the scale of the institutions and users using the network.

Digital Minister Nao Matsumoto apologized at a press conference after the Cabinet meeting on 11, saying that the matter was being taken very seriously, that security measures would be strengthened further, and that efforts would be made to prevent a recurrence. The key points confirmed at present are the possibility of a large-scale personal information leak and the intrusion route. Whether the information was misused and the specific scope of the ministries affected by the leak cannot be determined solely from the announced information.

References

Tags #JapanDigitalAgency #デジタル庁 #PersonalInformationLeak #GovernmentNetwork #IllegalAccess #VPNVulnerability #Cybersecurity #JapaneseGovernment #GovernmentSolutionService #GovernmentEmployeeInformation #InformationSecurity #MyNumber