[Security Radar] Japan Government System Hacked ... Toss Payments Merchant Payment Data Leaked
IT DAILY ·
✦ AI Summary
Japan's Digital Agency said it confirmed a breach of GSS and investigated signs that a maintenance contractor's account was used to access files in bulk by exploiting a vulnerability in VPN equipment.
It announced that about 246,000 records of personal information may have been leaked externally, including names, email addresses, and phone numbers.
Toss Payments said 4,131 payment records belonging to 2,671 customers were viewed because of a merchant's leaked integration key, and the FSS has launched an on-site inspection.
An attack targeting Japan's Government Common Tasks System (GSS) has raised concerns about a possible personal data leak. Japan's Digital Agency disclosed the circumstances of the GSS breach and the response measures, saying the intrusion was carried out by exploiting a vulnerability in VPN equipment. The investigation found signs of bulk file access through a maintenance contractor's account. According to the Digital Agency, about 246,000 records of personal information belonging to civil servants and business-related personnel may have been leaked, and the information that may have been exposed included names, email addresses, and phone numbers.
The Digital Agency said it applied a VPN security patch, suspended the account in question, and blocked external communications as response measures. The photo is courtesy of Japan's Digital Agency.
An incident also occurred at one Toss Payments merchant. The cause was the leakage of payment integration authentication information, and as a result, customers' payment information was transferred to a third party. According to Toss Payments, the scope of impact was 2,671 customers and 4,131 payment records. Toss Payments said this incident was not a direct hacking attack on its own systems. The Financial Supervisory Service is reportedly conducting an on-site inspection related to the incident.
External unauthorized access occurred in the Government Solution Service (GSS) operated by Japan's Digital Agency. On June 25, the agency launched an investigation after detecting signs of bulk file access on servers through a maintenance contractor's account.
On July 9, the Digital Agency confirmed that a third party had intruded by exploiting a vulnerability in VPN equipment. On the same day, it suspended the account and blocked communications between the compromised equipment and the outside.
The Digital Agency later conducted a joint investigation with an outside specialist firm and announced on the 11th that it had confirmed the possibility that personal information had been leaked externally. The possible leak involved about 246,000 records, including information on employees of GSS-using institutions and personnel involved in work for those institutions, and did not include personal information of ordinary citizens.
The data that may have been leaked consists of about 189,000 records of information on employees of GSS-using institutions and public officials involved in the work, as well as about 57,000 records of information on business operators and personal data. By item, counting duplicates, the figures were about 236,000 names, about 231,000 email addresses, about 94,000 phone numbers, and about 1,000 addresses. The Digital Agency said My Number, bank account information, and pension numbers were not included.
As of the 11th, the date of the announcement, the Digital Agency said no secondary damage such as misuse of personal information had been confirmed. It added that it plans to identify the affected individuals and notify them one by one in stages.
The Digital Agency urged caution regarding emails, phone calls, and text messages impersonating the agency. It also said it plans to review its vulnerability management methods to prevent recurrence.
The Digital Agency also said it plans to improve external access methods to prevent recurrence. With no secondary damage confirmed so far, it is moving ahead with individual notifications and warnings about impersonation contact while also signaling improvements to its management and access systems.
On the 9th, Toss Payments announced that 4,131 payment records belonging to 2,671 customers had been viewed by a third party at one merchant using its payment service. The company said the leak was not a direct hacking incident targeting Toss Payments' internal systems. The cause was the leakage of the authentication information, or the 'integration key,' used by the payment integration platform employed by the merchant.
Toss Payments said a third party used the leaked 'integration key' to view users' payment records. The information viewed included the buyer's name, a partially masked card number, and approval numbers. The company explained that information needed for payment, such as card passwords, expiration dates, and CVC, was not included. It said additional payments were therefore impossible.
After confirming the incident, Toss Payments blocked external access routes. It then analyzed access logs to determine the scope of impact and completed individual notifications to all affected customers.
Toss Payments reported the matter to the Financial Services Commission and the Financial Supervisory Service. The FSS has since launched an on-site inspection related to the case. The specific leak process and responsibility are expected to be confirmed through the investigation results.
Meanwhile, Kaspersky released its 'Quarterly Exploits and Vulnerability Report' on the 7th. According to Kaspersky, software vulnerabilities related to AI and large language models (LLM) totaled 935 in the second quarter of this year.
That figure was about 10 times higher than in the fourth quarter of last year. Of those, 119 vulnerabilities were rated Critical, up about 5 times over the same period. The photo caption stated that the number of publicly disclosed vulnerabilities in LLM, AI tools, and similar-function plugins in 2025-2026 was based on Kaspersky vulnerability management data.
In analyzing publicly disclosed vulnerabilities in LLM, AI tools, and similar-function plugins, Kaspersky pointed to inadequate access control over critical system objects, implementation flaws in authentication and authorization, and prompt injection vulnerabilities as key risks. Injection refers to a concept in which malicious commands or data inputs cause unintended behavior.
It also said attacks impersonating AI services are increasing. Kaspersky security solutions detected more than 33,300 attacks targeting small and midsize businesses from January to April this year, and the attack method involved malicious or unwanted PC software disguised as a well-known AI service. That detection volume was about 5 times higher than in the same period last year.
As countermeasures, Kaspersky recommended carrying out patch management in parallel, monitoring infrastructure and access-control status in real time, and continuously monitoring systems and access activity. It said the goal is to detect and block threats in a timely manner.
Source: IT DAILY · Kim Ho-jun
Original: https://www.itdaily.kr/news/articleView.html?idxno=241571
References
This article was produced with the help of an automated content generation algorithm.
Source: IT DAILY
View originalThis article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.