GMO’s ‘infoQ’ Leaks 950,000 Records, ¥2.87M Fraudulently Exchanged — 5ch: ‘Blame a Country With No Penalties’

From our other sites

The story

On October 5, GMO Research & AI announced that its survey site “infoQ” had suffered unauthorized access through an exploited vulnerability, leaking the personal information of up to 948,498 members. Of those, 611 accounts had a combined ¥2,869,500 in points exchanged for Amazon gift codes without the account holders’ consent, and the company says it plans to fully reimburse the fraudulently exchanged amounts. On 5ch, many users speculated that automated AI-driven attacks are on the rise and criticized Japan’s light penalties for data breaches, while others questioned the company’s past claims of strong security measures.

On October 5, GMO Research & AI announced that its survey site “infoQ” had been accessed without authorization through an exploited vulnerability, with up to 948,498 records — the entirety of its membership’s personal information — taken out externally. The service is currently suspended.

Details of the leak (from the news release)

In 611 of those cases, points were reportedly exchanged for Amazon gift codes (totaling ¥2,869,500) without the account holders’ consent. The company will fully reimburse the fraudulently exchanged points.

Source: news.yahoo.co.jp / Original article here

What people said

4AnonymousOct 6, 2026 11:42
It's gotta be either humans using AI to attack, or AI agents attacking on their own.
Probably the former.
29AnonymousOct 6, 2026 11:47
Yeah, it's definitely AI behind these.
Ever since that story about some AI going rogue broke, this stuff's been happening way too often.

Re: #4
Whether it's an organization or some individual, they're probably just blasting indiscriminate attacks everywhere.
7AnonymousOct 6, 2026 11:43
It's this country's fault for having no penalties for leaking data.
Say "sorry" and you get off scot-free.
191AnonymousOct 6, 2026 12:13
Re: #7
Seriously, this.
They need to crack down hard on anyone who leaks data.
Otherwise no company's ever going to spend the money to beef up security.
25AnonymousOct 6, 2026 11:46

GMO supposedly has world-class white-hat hackers on staff — so how did this happen?
76AnonymousOct 6, 2026 11:55
Re: #25
So the consultants were all talk, huh?
114AnonymousOct 6, 2026 12:03
Re: #25
Kind of like some famous karate master or something lol
33AnonymousOct 6, 2026 11:48
Wait, is the AI going to use Amazon gift codes to buy up GPUs and upgrade itself!?
166AnonymousOct 6, 2026 12:10
Re: #33
So humans are already enslaved, huh lol
50AnonymousOct 6, 2026 11:51
Are they coordinating the order of these announcements behind the scenes?
Something feels off.
66AnonymousOct 6, 2026 11:53
Re: #50
Some points site I used also suddenly went into maintenance and shut down completely yesterday.
Probably a ton of indiscriminate attacks going around and everyone's panicking.
91AnonymousOct 6, 2026 11:59
Re: #50
They're just piggybacking on the timing with their own announcement.
That way the bad impression gets diluted.
51AnonymousOct 6, 2026 11:51
Right now you can just blame it on AI and get away with it — it's basically a golden opportunity.
64AnonymousOct 6, 2026 11:53
What the heck is going on here?
Did a war break out in cyberspace or something?
93AnonymousOct 6, 2026 11:59
Isn't the only real countermeasure for this worldwide AI regulation?
Seriously, the moment something convenient gets invented, someone shows up to abuse it.

Re: #64
Since it got publicized that AI can pull off unauthorized access on its own,
there's probably people out there going "now's my chance" and using AI for indiscriminate attacks.
123AnonymousOct 6, 2026 12:04
Isn't the government going to do anything about this?
143AnonymousOct 6, 2026 12:07
Re: #123
Oh, they're already taking action — amending the law so leaking personal info isn't a problem anymore!
149AnonymousOct 6, 2026 12:08
You should spread your money across multiple accounts.
If you keep it all in one place and that account gets hit, you're done.
172AnonymousOct 6, 2026 12:11
What's the situation like in other countries?
Well, it's not making headlines elsewhere right now, so you can probably guess what that means.
203AnonymousOct 6, 2026 12:15
Re: #172
Re: #149
I've got my entire fortune parked at Mitsubishi UFJ, so I'm fine.
256AnonymousOct 6, 2026 12:21
Re: #172
This kind of thing has been happening worldwide for ages.
In 2024, a healthcare service provider in the UK suffered a massive ransomware attack — thousands of surgeries, appointments, and tests across multiple hospitals and clinics were cancelled, and one death is believed to be linked to the resulting disruption.
174AnonymousOct 6, 2026 12:11
Re: #141
Which screwup are you talking about?
181AnonymousOct 6, 2026 12:12
Re: #174
They screwed up last year, remember?
193AnonymousOct 6, 2026 12:14
Re: #181
Wasn't that one a phishing case?
I think the actual leak was at Rakuten Mobile.
223AnonymousOct 6, 2026 12:17
Re: #193
Right.
It was still unauthorized access either way, and the response was so bad that the Financial Services Agency came down on them — which led the whole industry to set up a compensation system.
Other online brokerages followed suit too.
252AnonymousOct 6, 2026 12:21
Re: #193
If you mess up yourself and get your password stolen,
there's nothing the company can do no matter how much security they put in place.
At that point the only option left is to block logins even when the correct password is entered.

Background and Key Points of This Story

Japan has no regulation that directly penalizes data leaks themselves — the Act on the Protection of Personal Information relies mainly on administrative guidance and recommendations, with nothing like the EU’s GDPR heavy fines. As a result, every time a leak happens, the same complaint — “the penalties are too light” — gets repeated, but no system designed to actually prevent recurrence has been put in place yet. It’s also easy to overlook that the announced figure of “up to 948,498 records” is simply the upper bound estimated at the time of the investigation, while confirmed fraudulent use was limited to 611 accounts totaling ¥2,869,500. The thread also included baseless accusations against China and other political comments, which this article does not adopt, as they are unsubstantiated speculation. Recently, in the case of unauthorized logins at Rakuten Securities, the Financial Services Agency issued administrative action and the industry moved to set up a compensation system — a similar response may be called for here as well.

*This article is excerpted and summarized from the 5ch (Breaking News+) thread “GMO’s ‘infoQ’ Hit by Unauthorized Access, Up to 950,000 Members’ Data Leaked — ¥2.87 Million in Points Fraudulently Exchanged“.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *