Key takeaways
- GMO Research & AI (GMOリサーチ&AI), part of Japan's GMO Internet group, says attackers exploited a software vulnerability in its survey site infoQ and took every member record it held: up to 948,498, including names, dates of birth, addresses, phone numbers and encrypted passwords.
- They also converted members' reward points into Amazon gift codes: 611 cases worth ¥2,869,500 (about US$19,000). The company will compensate all of it.
- The breach was found on October 3 after members reported problems. The attack had started the day before.
- For a Japanese breach notice, this one is unusual: instead of "no misuse has been confirmed", it says misuse did happen, and gives the numbers.
What happened#
infoQ is a survey site where members answer questionnaires for market research and earn points, which they can exchange for gift codes and other rewards. According to GMO Research & AI's notice:
| Date and time (2026) | Event |
|---|---|
| Oct 2 (Fri) onward | Unauthorized access by a third party, found later in the investigation |
| Oct 3 (Sat), morning | After inquiries from members, the company confirms the intrusion |
| 11:24 | Point exchange stopped (Amazon gift codes and GMO points) |
| 14:15 | Attack route cut off |
| 15:00 | External access to infoQ blocked; service stopped |
| Oct 5 (Mon) | Reported to the Personal Information Protection Commission. Notice published; members emailed |
The attackers got in by exploiting a vulnerability in software used on the site. The company has not named the software, and is investigating with a security firm.
While the site was down, it told visitors it was in "emergency maintenance". The notice now says the outage was caused by the attack, and apologizes for the late explanation.
What was taken#
| Data | Status |
|---|---|
| Name and its reading, gender, date of birth | Taken |
| Email address, home address, phone number | Taken |
| Password (encrypted), member ID | Taken |
| Nickname, points balance, last survey answered | Taken |
| Payment card data, My Number (national ID number) | Not held |
The 948,498 records are all the personal data the company holds for infoQ. Data on the company's business clients was not included, and no access to its other services has been found.
The point fraud#
On top of the data theft, 611 members' points were exchanged for Amazon gift codes without their consent, worth ¥2,869,500 in total, about ¥4,700 per case on average. GMO Research & AI says it will compensate the full amount. It asks members who notice an exchange they did not make to contact its support desk.
What we don't know yet#
GMO Research & AI has not said:
- Which software was vulnerable: a commercial or open-source product, or code written for infoQ itself
- How the attackers were able to exchange points: whether through members' accounts or directly through the system
- Whether the encrypted passwords could be cracked
- Whether the Amazon gift codes have been cancelled or traced
- Whether it has reported the fraud to the police
- When infoQ will reopen
Our analysis#
"Misuse confirmed", with numbers#
Most Japanese breach notices say the same thing: no secondary harm has been confirmed at this time. We have argued that this usually means no one has reported any yet, not that none has happened. This notice is a rare exception. It says misuse happened, counts it (611 cases), puts a yen figure on it, and commits to paying it back.
That candor deserves credit. It also shows what the "not confirmed" line can hide. Here the attackers monetized their access within a day, before the company knew it had been breached. The same was true at ABAHOUSE, where stolen order data was turned into scam emails within about a day. The difference is that points leave a record the company can count. Scam emails sent to customers do not.
Points are money#
Reward points look like a marketing tool. Once they can be exchanged for gift codes, they are a currency. Amazon gift codes in particular are easy to sell on and hard to trace back, which is why they are a common target for attackers who break into point and loyalty systems. A survey site holds many small balances, and attackers drained 611 of them in a short time. The company stopped point exchanges at 11:24 on October 3, more than three hours before it cut off the attack route. That ordering suggests it saw the points as the most urgent loss.
Found by members, again#
As at ABAHOUSE, the company learned of the breach from members' inquiries, not from its own monitoring. A system that can turn points into gift codes would normally be watched for unusual exchanges. The notice does not say what monitoring was in place.
"Emergency maintenance"#
infoQ told visitors it was down for "emergency maintenance" while it was, in fact, responding to an attack. GMO Research & AI has now said so and apologized, which is better than not saying so. But it is a pattern we keep seeing: Rakuten Drive described the suspension of its app downloads in September as "system maintenance", two weeks before disclosing its breach. Calling incident response "maintenance" may buy time, but it leaves users without the information they need to protect themselves.
A product, or the site's own code?#
The company says a vulnerability in software used on the site was exploited, but not which software. If it was a widely used product, other companies running it need to know, and naming it once fixed would help them check their own systems.
But it may not have been a product at all. This is speculation on our part: neither GMO Research & AI nor the other companies whose breaches we have covered in recent weeks have said whether the flaw was in a widely used product or in their own application. It is possible that some of these breaches exploited how each company built its own system, rather than a known flaw in a popular product.
If so, it would not be surprising. Code written for a single site is reviewed by far fewer people than a widely used product or open-source project, and its flaws never appear in public security advisories. And as AI makes finding vulnerabilities faster, as described in IPA's white paper, attackers may not need a known flaw in a popular product: they could look for one in each company's own application. If infoQ's weakness was in its own code, saying so would matter as much as naming a product. It would tell other companies that the lesson is to test their own applications, not only to apply patches.
What this means for readers#
- If you are an infoQ member, assume your name, date of birth, address, phone number and email address are in the hands of criminals. Expect emails, texts or calls about points, rewards, compensation or surveys that pretend to be from infoQ or GMO.
- Change your password on any other service where you used the same one as infoQ. The infoQ password was stored encrypted, but the company itself recommends this.
- Check your point history when infoQ reopens, and report any exchange you did not make.
- If you run a points or rewards system, monitor exchanges for unusual volume and timing, and have a way to stop them quickly. infoQ's fastest action on the day was stopping point exchanges.
Japanese terms at a glance#
| Japanese | Reading | Meaning |
|---|---|---|
| アンケートサイト | ankēto saito | Survey site |
| ポイント交換 | pointo kōkan | Point exchange (for gift codes or other rewards) |
| ギフトコード | gifuto kōdo | Gift code |
| 全額を補填 | zengaku o hoten | Compensate the full amount |
| 緊急メンテナンス | kinkyū mentenansu | Emergency maintenance |
| ソフトウェアの脆弱性 | sofutowea no zeijakusei | Software vulnerability |
| 二次被害 | niji higai | Secondary harm (misuse of leaked data) |
We will update this article when GMO Research & AI publishes the results of its investigation.