SHINDO5

Government Solution Service (GSS)

Personal data records~246,000records

POSSIBLE LEAKPostal address / Phone numberUnauthorized access · Contained

Open in the live monitor ▶
Disclosed
Sep 11, 2026
Detected
Jun 25, 2026
Detection to disclosure
78 days
Leak
Leak possible
Type
Unauthorized access
Status
Contained
Security spend
Measures, no amount
Compensation
Not announced

What leaked

IdentityFull name
ContactEmail address, Phone number, Address

Not leaked

  • My Number, bank account information, pension numbers and the like are not included
  • My Number, bank account information, pension numbers and the like are not included

How many

  • Personal data records ~246,000 records
  • Government staff and public servants ~189,000 records
  • Contractors and individuals ~57,000 records

Who is affected

  • Staff of agencies using GSS
  • People involved in that work

Cause

A third party exploited a vulnerability in a VPN device used for remote maintenance, entered GSS, and used a maintenance operator's account to access a large number of files on the servers

Timeline

  1. Around late May
  2. Detected
  3. Intrusion via the VPN device vulnerability confirmed
  4. Reported to authority
  5. First disclosure

Response

  • Revoked credentials
  • Blocked the entry point
  • Patched
  • Notified individuals
  • Hotline

Suspended the compromised account, cut external communications, addressed the VPN device vulnerability and is reviewing the connection method. Affected people are being identified and contacted individually in turn. Dedicated helpline (0120-360-036)

What you should do

  1. Don't open links in emails from this company. The apology email itself may be fake
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Watch for unexpected mail or invoices; your address is hard to change
  4. Expect targeted phishing posing as HR or interview contacts
  5. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources