GMO Research & AI Inc., a subsidiary of Japan's GMO Internet Group, has said an attacker accessed its server without authorization and may have taken nearly its whole member database. The breach hit infoQ, the company's paid-survey platform. Reported figures range from "up to 948,500" records (Kyodo News, citing the company's statement) to an exact 948,498 (Hakky Handbook and BigGo Finance). Hakky calls that number "the entirety of its member database." The attacker also took money. About 2.87 million yen (roughly $18,000) in member reward points was turned into Amazon gift card codes without the owners' consent. The company has suspended infoQ. No statement from the company itself or from a regulator was among the sources for this brief, so every detail below is attributed to the outlet that reported it.
What Happened
BigGo's account gives the most detailed timeline. According to BigGo, the unauthorized access began on October 2, 2026. The company started investigating on October 3 after members contacted it, and it took the service offline the same day. BigGo also reports that the functions for exchanging points into Amazon gift codes and GMO Points were turned off. That detail matters because the reward system was the attacker's route to cash.
Sources disagree on when the company went public. Kyodo News says the statement came out on Monday, which was October 5. Hakky also gives October 5. BigGo gives October 6. The gap may just reflect time zones or when each outlet published, but it is unresolved.
Hakky reports that the company is reporting the incident to Japan's Personal Information Protection Commission (PPC) and notifying affected users. BigGo reports that GMO Research & AI plans to fully compensate members whose points were stolen.
What Was Taken
Volume. Every source puts the count at about 950,000, but the precision varies: - "Up to 948,500" (Kyodo News, citing the company) - 948,498 (Hakky Handbook; BigGo Finance) - "Approximately 950,000" members, given as context (Hakky; BigGo headline)
BigGo adds a point that matters for reading the number. The ceiling includes former members who had already left the service, whose data had supposedly been processed so it could no longer be viewed. The company is still working out how many records were actually exfiltrated. The final confirmed number could therefore be lower than the headline figure.
Data types. The sources describe the stolen data very differently: - Hakky says only that the stolen information "is believed to include members' names and contact details." - BigGo gives a much longer list: names, dates of birth, email addresses, home addresses, phone numbers, encrypted passwords, and member IDs.
Only BigGo reports the fuller list, and that has not been independently confirmed. Treat it as likely but unverified until the company publishes its own disclosure. BigGo also reports that GMO Research & AI does not store credit card data or My Number (Japan's national ID number), so neither was exposed.
Reward fraud. Kyodo, Hakky, and BigGo all agree that member points were cashed out as Amazon gift codes. Kyodo gives the value as about 2.9 million yen. Hakky and BigGo both give the exact figure of 2,869,500 yen. They disagree on what the number 611 counts. Hakky says 611 accounts were used. BigGo says 611 transactions. One account can make several transactions, so the number of affected members could be 611 or fewer.
Why It Matters
Survey panels are very attractive targets. Hakky makes this point directly. A research panel holds detailed demographic data (names, addresses, ages, occupations) along with point balances that can be turned into cash. If an attacker gets in, they can sell the data and also drain the stored value.
This attack moved from data theft to cashing out within about a day. Going by BigGo's timeline, access began on October 2 and members were already complaining on October 3. That means points were converted into gift codes almost immediately. Hakky notes that spotting a data breach and spotting fraudulent redemptions are separate monitoring problems that show up at different stages of an attack. In this case, it was customer complaints, not internal detection, that started the investigation.
Former members are also exposed. If BigGo is right that people who had left the service are included, the company kept their data in a recoverable form after they left. That is a data-minimization failure, and it widens the impact well beyond current users. It is also exactly the kind of issue the PPC is likely to examine.
The follow-on risk is phishing. Names, emails, home addresses, phone numbers, and dates of birth from almost a million Japanese consumers are well suited to targeted phishing. Expect lures that pretend to be infoQ, GMO, or Amazon and that mention "compensation" or "point restoration." If encrypted password data was taken, as BigGo reports, credential stuffing is also a risk wherever members reused their infoQ password.
Context from the wider source set. One BigGo report from September 30 shows that GMO Research & AI ran a survey for Dell Technologies Japan. In that survey, 78.5% of large Japanese companies said they had a security incident linked to generative AI in the past year, and data leakage was the most common type. None of the other sources in this set cover the infoQ incident. FedScoop's report on the Baylor Genetics breach, where the US Department of Veterans Affairs criticized slow and incomplete notification, is a reminder that regulators and partners are paying close attention to disclosure speed. Coverage of OpenAI agents probing government and university sites (The Decoder, The Canberra Times, TechRepublic) describes a separate set of events and gives no indication of who was behind the GMO breach.
The Attack Technique
Very little has been disclosed. Kyodo and BigGo describe the attack only as unauthorized access to the company's server. Hakky, whose article was AI-generated, says the attack exploited a vulnerability, but it does not name the vulnerability, the affected component, or any CVE. No threat actor has been named, and no group has claimed the attack in any of the sources reviewed. Hakky reports that the company is still investigating how the attacker got in and how far the damage goes.
From what is known, the sequence looks like this: 1. The attacker got in, apparently through a flaw in the web application or server (attributed to Hakky). 2. The attacker extracted the member database in bulk. 3. The attacker redeemed points from member accounts as Amazon gift codes, which are easy to resell and hard to claw back.
It has not been disclosed whether the attacker redeemed points by logging into accounts with stolen credentials or by manipulating the redemption system directly on the back end. The answer will matter when judging how much the password data was actually exposed.
What Organizations Should Do
- Put velocity and anomaly controls on redemptions. Treat converting points to gift cards like a payment. Rate-limit redemptions per account and across the platform, flag spikes in redemptions to high-liquidity rewards such as Amazon codes, and require step-up verification (for example, re-entering a password or an email OTP) before cashing out.
- Monitor the value layer separately from the data layer. Don't count on breach detection to catch fraud, or the other way round. Alert on sudden changes in redemption volume so that the first sign of trouble is not member complaints.
- Actually delete data for departed users. Records that are hidden but still recoverable are still a liability. Enforce retention limits and irreversible deletion or anonymization for users who have left.
- Patch and test internet-facing applications aggressively. For platforms that hold both PII and stored value, run regular authenticated application tests, use a WAF, and set a tight patch SLA for public-facing components.
- Prepare for phishing that exploits the breach. If you serve Japanese consumers, warn users now about fake "infoQ compensation" and "GMO point refund" messages, and tune email filters for those themes.
- Hash passwords properly and force resets after a breach. Use a modern, salted, slow hash such as Argon2id or bcrypt rather than reversible encryption. Invalidate sessions and require password resets as soon as you suspect data was taken.
Sources: URGENT: Japan's GMO Research & AI says up to 948,500 member records... | 30,000-plus veterans affected by Baylor Genetics’ cybersecurity bre... | Unauthorized Access to infoQ: 950k User Records Leaked Hakky Handbook | Unauthorized Access Hits GMO-Affiliated Survey Site in Japan ... | Nearly 80% of Japanese Companies Report Security Incidents ... | AI Expansion, Robot Factories, and Escalating Security Threats ... | OpenAI's agents went after government and university sites months b... | Hack probed with warnings it's 'too late' to contain AI The Canber...