Japan’s Digital Agency ordered spot audits of municipal VPN configurations on Friday after usernames and one-time passwords stolen from a Kagawa town hall were listed on a criminal marketplace, exposing remote access paths to property tax systems.
The agency told prefectural IT chiefs to verify multifactor settings on appliances from three major vendors within two weeks. Kagawa officials said the town disabled external VPN ports on Wednesday after a vendor tip, containing the breach before payroll files were accessed.
How the credentials leaked
According to a JPCERT/CC coordination note shared with municipalities, attackers phished a part-time clerk who reused a help-desk password on the town’s SSL-VPN portal. The stolen session cookie allowed download of a configuration backup that included hashed credentials for 42 accounts.
Marketplace listings appeared in English and Russian forums; no ransomware deployment followed, suggesting the seller sought quick resale rather than extortion.
Audit checklist
Digital Agency templates require cities to disable legacy cipher suites, enforce hardware tokens for finance roles, and segment VPN pools so clerks cannot reach industrial control networks used in water plants. Many smaller towns purchased identical appliances during pandemic telework grants and never revisited defaults.
The agency will publish anonymized findings in November. Noncompliant municipalities risk losing subsidies for zero-trust migration projects scheduled for fiscal 2027.
Vendor and insurer response
Two appliance makers issued firmware builds that block bulk configuration exports unless a second administrator approves. Cyber insurers covering municipal governments raised premiums 6 percent on average this quarter, citing similar incidents in Shikoku and Tohoku.
Kagawa’s prefectural government set up a hotline for towns to report scan results, staffed by contractors through October.
What residents might notice
Residents scheduling in-person tax appointments may face longer phone holds while cities rotate VPN passwords. The agency asked towns to avoid suspending outward-facing payment portals unless active intrusion is confirmed.
Lessons for school boards
Because many towns share IT contractors with prefectural school networks, the Digital Agency extended the audit template to boards of education serving more than 5,000 students. Shared VPN pools between city halls and schools were a common misconfiguration in 2024 phishing drills.
Training videos with English subtitles will ship to municipal portals by 10 October, emphasizing that clerks should not approve MFA resets over the phone without callback verification.
Audit scope
Digital Agency reviewers sampled 42 prefectural and municipal VPN gateways after credentials tied to a Kagawa waterworks contractor appeared on a dark-web market. The leak did not expose citizen tax data, officials said, but it proved remote-maintenance accounts outlasted employee departures.
Agency checklists now require multifactor authentication on every vendor tunnel and quarterly password rotation with break-glass exceptions logged centrally. Smaller towns that outsourced IT to regional cooperatives struggled to produce complete user lists within the 48-hour deadline, triggering follow-up visits in October.
Opposition lawmakers asked whether the audit would extend to school boards still running legacy SSL-VPN appliances; the agency said education networks are Phase Two after water and transit systems.
Water utilities nationwide received template incident-response playbooks on Friday, including sample press lines if contractor credentials leak again during typhoon repair season.
Vendor contracts
Municipal lawyers were told to insert clawback clauses when VPN credentials leak through vendor negligence, a step Kagawa’s water bureau now models for other utilities. The Digital Agency will publish anonymized findings in November so towns can compare MFA adoption without naming failed audits publicly.
