← Blog

GMO infoQ Breach: Up to 948K Members, Gift-Card Fraud

Share on X

GMO Research & AI shut down its infoQ survey panel on October 3, 2026 after finding unauthorized access tied to a software vulnerability exploited from October 2, exposing up to 948,498 member records and fueling 611 unauthorized Amazon gift-card redemptions worth ¥2,869,500 in points. Notice: notice-20261005. Canonical: https://breachhistory.com/gmo-research-ai/gmo-research-infoq2026 (/gmo-research-ai/gmo-research-infoq2026).

This is a verified GMO infoQ data breach — the company confirms intrusion, member-data removal, point fraud, and service suspension — not a leak-site rumor. What this is not: a compromise of GMO’s unrelated hosting or research products; the notice says other GMO Research & AI services showed no unauthorized access at indexing time.

What happened — vulnerability to full shutdown

Forensics traced the incident to a third party abusing a vulnerability in software used on the infoQ site. Attackers accessed the server, exfiltrated member personal data GMO held for the panel, and manipulated loyalty points for some accounts.

GMO discovered the intrusion on Saturday, October 3, 2026, after member inquiries prompted investigation — a reminder that user reports still catch incidents automated alerts miss. The same day GMO halted point exchanges, blocked the attack path, and cut external access entirely, leaving the public site on “emergency maintenance” messaging that actually reflected breach response.

Timeline

  1. October 2, 2026 onward — Unauthorized access occurs (exact clock time not published).
  2. October 3, 2026 (morning) — Member contacts trigger investigation; intrusion confirmed.
  3. October 3, 2026, 11:24 — Point exchanges stopped (Amazon gift cards and GMO points).
  4. October 3, 2026, 14:15 — Attack path blocked.
  5. October 3, 2026, 15:00 — External access to infoQ shut; service suspended.
  6. October 5, 2026 — Report to Personal Information Protection Commission; public notice; member emails begin.

What remains under investigation

  • CVE or vendor name for the vulnerable software component.
  • Whether encrypted passwords were cracked or reused before GMO forced resets.
  • Full list of fraudulent gift-card codes — GMO promises reimbursement but has not published technical IoCs for members.

What data was exposed

GMO says the breach covers all personal information it held on members — maximum 948,498 records as of October 5. Fields include:

  • Name and furigana
  • Gender and date of birth
  • Email address, postal address, phone number
  • Encrypted password
  • Member ID
  • Other registration metadata — nickname, point balance, last survey date, usage status fields

That is a full panel profile — valuable for targeted phishing (“complete survey ID 948xxx”) and for credential attacks if passwords were weak before encryption.

What was not exposed

GMO states it does not store credit card numbers or My Number national IDs on infoQ. Panel rewards flow through points and gift codes rather than direct card-on-file billing in this notice’s framing.

Point fraud — 611 accounts, ¥2.8695 million

Separate from static data theft, attackers redeemed points without consent for 611 members, converting ¥2,869,500 worth into Amazon gift codes. GMO commits to replacing all stolen points — good customer remediation, but it confirms attackers had session or API-level power, not just read-only database access.

If you noticed missing points before October 3, you may have been in that subset even before email notice arrives.

How the attack likely worked

“Software vulnerability exploitation” on a public-facing survey property usually means unpatched web code — injection, authentication bypass, or file inclusion — leading to database access. GMO engaged external security firms for deeper forensics but had not published CVE details in the October 5 notice indexed here.

Defenders running similar panel sites should patch aggressively, disable point redemption until MFA-reviewed, and monitor for anomalous gift-card generation rates — GMO’s 11:24 exchange halt shows the fraud window was measured in hours, not weeks.

Who is at risk

All infoQ members — the count equals GMO’s entire stored personal-data population.

People reusing infoQ passwords elsewhere — GMO recommends rotation on other sites if you recycled the same string.

Survey participants targeted by scammers who know your nickname, points, and last activity date — fields GMO lists explicitly.

Corporate clients commissioning research — GMO says client data was not in the stolen set, but fieldwork schedules may slip while infoQ is offline.

Phishing after the GMO infoQ breach 2026

  • Fake “reactivate infoQ account” pages harvesting passwords under maintenance pretense.
  • Survey invites with malware attachments quoting your real nickname.
  • Amazon gift-code “confirmation” emails tied to the fraud subset — verify through GMO support only.

Service suspension and client impact

infoQ remains down while GMO validates security before reopening. The notice apologizes to research clients whose projects pause — a operational ripple distinct from member PII harm but relevant if you participate in GMO panels for side income.

What GMO asked members to do

  1. Change passwords on other services if you reused your infoQ password.
  2. Ignore impersonation email, SMS, and phone calls claiming to be GMO or infoQ.
  3. Report unexplained point exchanges to [email protected].
  4. Wait for official email starting October 5 rather than trusting forum dumps.

Was I affected?

If you held an infoQ account, assume inclusion in the 948,498 maximum until GMO narrows the set — the company itself equates the breach count with all personal data on file. Check email and point history; GMO will reimburse confirmed fraudulent redemptions.

Encrypted passwords — member action

GMO stores passwords encrypted/hashed, but offline cracking still threatens weak choices. Treat encrypted status as reducing immediate plaintext exposure, not eliminating rotation. Enable MFA on email used for infoQ registration because password-reset flows often live there.

Regulatory and group context

GMO Research & AI sits inside the broader GMO Internet Group security marketing orbit — the notice lands amid group-wide breach-awareness campaigns. Regulator reporting on October 5 signals APPI compliance steps; watch for supplemental commission guidance in Japanese.

Comparison with contact-only retail leaks

infoQ rows bundle demographics, addresses, and survey behavior — richer than a bare email list from a takeout app. Fraudsters can tailor social-engineering to “you have 1,200 points expiring” because points were in the stolen metadata set.

Technical notes for panel operators

  • Separate point-redemption APIs behind step-up authentication and fraud velocity checks.
  • Freeze gift-card issuance when WAF alerts spike on survey login paths.
  • Prepare maintenance messaging that is honest about security incidents — GMO later clarified “maintenance” meant breach response.

Long-term monitoring

GMO promises another notice when it confirms safe reopening and final root-cause remediation. Until then, assume your panel profile is in criminal circulation, watch for gift-card fraud on linked Amazon accounts, and document any impersonation attempts for support.

What infoQ is in GMO’s portfolio

infoQ is a consumer survey panel operated by GMO Research & AI, paying points for questionnaire completion and redeeming those points for gift cards including Amazon codes. Panelists trade detailed demographics for micro-rewards — which means the database naturally accumulates rich PII ideal for fraud if stolen.

October 2 entry vs October 3 discovery

The notice separates first unauthorized access on October 2 from operational discovery on October 3. Attackers had at least hours to exfiltrate and script point redemptions before GMO blocked exchanges at 11:24. Short windows still suffice for automated gift-card generation when redemption APIs lack rate limits.

Maintenance messaging honesty

GMO apologizes for labeling the outage “emergency maintenance” before explaining the breach — a transparency lesson for comms teams. Users who guessed security trouble were correct; others may have delayed password changes thinking it was routine patching.

Point economy as monetization path

Stealing databases is one revenue line; draining points is another. ¥2,869,500 across 611 accounts averages roughly ¥4,700 per abused member — meaningful at panel scale. GMO’s full reimbursement promise reduces customer loss but confirms attackers achieved write-level capabilities, not read-only SQL dumps.

Amazon gift code fraud mechanics

Gift codes behave like cash on marketplaces. Criminals automate redemption or resell codes quickly before victims notice point balance drops. If your Amazon account email matches infoQ registration, watch for unexpected digital orders or code applications.

Full-population exposure semantics

When GMO equates 948,498 with all personal data held, there is no “maybe safe if I was inactive” carve-out — dormant accounts still carry registration history, nicknames, and last-answer timestamps useful for social engineering.

Encrypted password field

Panel users often choose weak passwords because the asset feels low-risk — “just surveys.” Bulk encrypted hashes invite offline cracking. Rotate any password shared with email, shopping, or banking portals regardless of GMO’s encryption wording.

Client research continuity

Corporate clients commissioning surveys face project delays while infoQ is offline. GMO says client data was not stolen; still, fieldwork pauses may breach contract timelines — a B2B angle separate from member PII but relevant for Japan’s research industry this quarter.

Other GMO services isolated

The notice states no unauthorized access to non-infoQ GMO Research & AI properties at detection time. Users with accounts on other GMO panels should not assume cross-compromise without separate notices.

Support channel discipline

[email protected] accepts mail 24/7 with human response on business days. Scammers may register look-alike domains — verify TLS certificates and SPF-aligned senders before submitting ticket numbers or ID scans.

Survey phishing with real metadata

Attackers who know your nickname and last response date can draft Japanese emails indistinguishable from legitimate fieldwork invitations — except for URL domains. Always cross-check survey links against infoQ’s historical domain patterns stored in your password manager.

Regulatory reporting October 5

PPC notification on October 5 aligns with APPI expectations after confirming personal-data theft. Additional commission statements may follow; they do not automatically email each member.

Reopening criteria

GMO promises service restoration only after safety validation and recurrence-prevention measures — unspecified in the first notice. Expect mandatory password resets or MFA enrollment on relaunch even if not yet announced.

Comparison with credential-only leaks

infoQ combines secrets (password hashes) with behavior (points, dates). Defensive priority: email MFA first, then password rotation, then monitor gift-card balances.

Incident timeline for SOC teams

Replay GMO’s same-day sequencing — user report, exchange halt, path block, external cut — as a tabletop benchmark for your own panel or loyalty program. Hours matter when points convert to cash-equivalent codes.

¥2.8695 million fraud subset math

611 accounts averaging near ¥4,700 in stolen points illustrates selective targeting — likely accounts with high balances or weak step-up controls on redemption. Low-balance members still face full PII exposure even if their points stayed untouched.

Furigana and legal-name pairing

Japanese fraudsters use furigana plus kanji names to bypass bank KYC phone scripts. Combined with address and DOB, the infoQ bundle approaches loan-application grade identity data for some members.

infoQ niche vs mega-retail breaches

Panel breaches rarely match retail headcounts but often exceed retail field richness per row. Adjust identity monitoring intensity to field mix, not headline population size alone.

GMO Internet Group security marketing

The notice footer references group security services — irrelevant to remediation but signals corporate awareness expectations. Members may receive upsell mail; separate incident support from product marketing carefully.

October 5 email batch

Sequential email from October 5 may take days for nearly one million members. Check spam folders and legacy addresses you used when joining years ago.

Panelists treating infoQ as side income

Many infoQ members treat points as small side income — losing a gift-card redemption hurts household budgets even when GMO reimburses. Document unauthorized Amazon code generation with timestamps and screenshots before redeeming replacement points, in case support tickets require evidence.

Vulnerability disclosure expectations

GMO has not yet named the flawed software package in the October 5 notice. When CVE or vendor patch notes arrive, other survey operators should test the same component in their stacks. Until then, assume common web-app classes — injection, auth bypass, file upload — without speculating a specific product.

Tax and survey income records

Panelists who redeemed points for gift cards may need records for tax or household budgeting. After reimbursement, export GMO point history once infoQ returns so you can reconcile which redemptions were fraudulent versus legitimate before October 3.

Corporate comms teams at GMO clients

If your employer hired GMO Research surveys, separate internal project data from infoQ member PII — GMO says client commissioning data was not in the stolen member set. Still pause fieldwork until GMO confirms reopening timelines so you do not accidentally send new PII into a frozen environment.

For members asking whether the GMO infoQ breach 2026 affects them, the company’s own ceiling — 948,498 records with October 2 exploitation and October 3 shutdown — means every stored panel profile should be treated as exposed until GMO publishes a narrower forensic subset.

Rotate infoQ passwords on other sites, enable MFA on email, and file support tickets if Amazon gift codes appeared without your consent — GMO has already quantified that fraud at ¥2,869,500 across 611 accounts and promised reimbursement.

Bookmark the canonical GMO Research infoQ breach record at BreachHistory for count or reopening updates rather than trusting reposts that inflate victim numbers beyond the 948,498 member ceiling GMO documented on October 5.

Canonical record and sources

BreachHistory indexes GMO infoQ as company-confirmed with 948,498 members, software-flaw entry, service suspended October 3, and ¥2,869,500 point fraud across 611 accounts. Update at https://breachhistory.com/gmo-research-ai/gmo-research-infoq2026.

infoQ members should treat October 2–3 as the active compromise window, rotate reused passwords, report missing points, and expect panel downtime until GMO certifies fixes — while remembering the stolen bundle includes enough survey metadata to power convincing fake research invitations.