Japan’s Digital Agency said its Government Solutions Service (GSS) network was accessed without authorization through a maintenance account in late June. The attacker exploited a virtual private network (VPN) vulnerability to extract files at scale, potentially exposing the names, email addresses and phone numbers of about 246,000 public officials and related personnel using the system. The agency said it has not identified any improper use directly linked to the incident. Japan recorded 123 ransomware attacks nationwide in the first half of this year, the highest half-year total since government statistics began.