2026 GMO Research infoQ — software vuln; up to 948,498 members + gift-code fraud
Data compromised
Up to 948,498 members (incl. withdrawn): name, DOB, email, home address, phone, encrypted password, member ID. No credit cards or My Number retained. Secondary: ¥2,869,500 in member points fraudulently exchanged for Amazon gift codes across 611 transactions — company pledges full reimbursement.
Technical writeup
Verified company notice — GMO Research & AI Oct 5/6, 2026: unauthorized access to survey site infoQ after software vulnerability exploitation from Oct 2; service suspended Oct 3. Up to 948,498 member records may have leaked (includes withdrawn members; exact unique count under review): name, DOB, email, address, phone, encrypted password, member ID. Cards and My Number not held. Separately, 611 fraudulent point exchanges totaling ¥2.8695M to Amazon gift codes; full reimbursement pledged; Amazon/GMO Points exchange functions suspended. recordsAffected 948498; companyConfirmed true.
Root cause
Third party exploited a software vulnerability beginning Oct 2, 2026; unauthorized access confirmed Oct 3; infoQ service suspended.