SHINDO5
Government Solution Service (GSS)
Digital Agency
Personal data records~246,000records
POSSIBLE LEAKPostal address / Phone numberUnauthorized access · Contained
Open in the live monitor ▶- Disclosed
- Sep 11, 2026
- Detected
- Jun 25, 2026
- Detection to disclosure
- 78 days
- Leak
- Leak possible
- Type
- Unauthorized access
- Status
- Contained
- Security spend
- Measures, no amount
- Compensation
- Not announced
What leaked
IdentityFull name
ContactEmail address, Phone number, Address
Not leaked
- My Number, bank account information, pension numbers and the like are not included
- My Number, bank account information, pension numbers and the like are not included
How many
- Personal data records ~246,000 records
- Government staff and public servants ~189,000 records
- Contractors and individuals ~57,000 records
Who is affected
- Staff of agencies using GSS
- People involved in that work
Cause
A third party exploited a vulnerability in a VPN device used for remote maintenance, entered GSS, and used a maintenance operator's account to access a large number of files on the servers
Timeline
- Around late May
- Detected
- Intrusion via the VPN device vulnerability confirmed
- Reported to authority
- First disclosure
Response
- Revoked credentials
- Blocked the entry point
- Patched
- Notified individuals
- Hotline
Suspended the compromised account, cut external communications, addressed the VPN device vulnerability and is reviewing the connection method. Affected people are being identified and contacted individually in turn. Dedicated helpline (0120-360-036)
What you should do
- Don't open links in emails from this company. The apology email itself may be fake
- Treat refund or apology calls and texts as scams. Call back only on the number from the official site
- Watch for unexpected mail or invoices; your address is hard to change
- Expect targeted phishing posing as HR or interview contacts
- Check the company's notice to see if you're affected
Lessons for companies
- Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
- Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
- Run red teaming and AI-assisted hardening, and publish how much you invest
Sources
- Digital Agency Official notice · Sep 11, 2026
- piyolog Researcher · Sep 11, 2026
- Security NEXT News · Sep 11, 2026