❓ What happened?
On September 11, 2026, Japan's Digital Agency announced that the Government Solution Service (GSS) — the shared IT platform it operates for government bodies — had been accessed without authorization from outside, and that some files containing personal information handled on GSS may have leaked.
The timeline: on June 25, 2026, the agency detected that a maintenance operator's account was being used to access large volumes of files on a server, and opened an investigation. On July 9 it confirmed that a third party had broken into the system by exploiting a vulnerability in a network connection device (VPN). The same day it suspended that account and cut off communication between the compromised device and the outside, stopping further unauthorized access. A follow-up investigation with outside specialists confirmed that personal data may have left the system.
About 246,000 records may have been exposed: roughly 189,000 belonging to staff of GSS-using ministries and agencies and public officials involved in their work (including staff of incorporated administrative agencies), and roughly 57,000 belonging to companies and individuals engaged in that work. By item (with overlap): names about 236,000, email addresses about 231,000, phone numbers about 94,000, addresses about 1,000.
My Number, bank account details and pension numbers were confirmed not to be included. The data concerns government staff and people who worked with them — personal information of the general public is not involved. The agency says it will review its vulnerability management and improve how external connections are made.
🌏 Impact on foreign residents
Those directly affected are government staff and the companies and individuals who worked with them. If you are a foreign resident who has taken on a government project — as an interpreter, translator, IT engineer, designer, or researcher, whether freelance or as a company employee — your name, email address and phone number may be among the records. The Digital Agency says it will identify affected people and contact them individually in stages, so until you hear from them you cannot know whether you are on the list.
The second risk touches far more people: scams riding on the news. The agency explicitly warns that the data could be abused for impostor and phishing emails. Expect Japanese- or English-language emails and SMS claiming to be from the "Digital Agency" or "Mynaportal" and pushing you to a page that asks for a password or credit card number. Foreign residents who are less used to official Japanese documents are the most likely to have trouble telling real from fake.
The Digital Agency never asks for authentication credentials or credit card details by email or phone. As of the announcement, no secondary damage such as misuse of the leaked data has been confirmed.
💡 Key points to know
1You will learn whether you are affected through individual contact from the Digital Agency; it is identifying those concerned and notifying them in stages
2For questions, call the dedicated toll-free line 0120-360-036 (GSS Team, Ministry Operations Service Group), or email kojin-info@digital.go.jp (the official page writes "@" as "_atmark_" as an anti-spam measure)
3Be wary of suspicious email, phone calls and SMS claiming to be from the Digital Agency or related bodies. Do not open links or attachments in messages you did not expect
4The Digital Agency never asks for passwords or other credentials, or credit card details, by email or phone
5If you have ever taken on government work, watch the email address you registered at that time especially closely, and tighten your spam filter if needed
6Email addresses are the largest category (~231,000), so email is the most likely entry point for scams. For anything important, look up the official number yourself and call back to verify
7My Number, bank account details and pension numbers are not among the potentially leaked data — any message demanding them should be treated as a scam