From our other sites
The story
On October 5, GMO Research & AI announced that its survey site “infoQ” had suffered unauthorized access through an exploited vulnerability, leaking the personal information of up to 948,498 members. Of those, 611 accounts had a combined ¥2,869,500 in points exchanged for Amazon gift codes without the account holders’ consent, and the company says it plans to fully reimburse the fraudulently exchanged amounts. On 5ch, many users speculated that automated AI-driven attacks are on the rise and criticized Japan’s light penalties for data breaches, while others questioned the company’s past claims of strong security measures.
On October 5, GMO Research & AI announced that its survey site “infoQ” had been accessed without authorization through an exploited vulnerability, with up to 948,498 records — the entirety of its membership’s personal information — taken out externally. The service is currently suspended.
Details of the leak (from the news release)
In 611 of those cases, points were reportedly exchanged for Amazon gift codes (totaling ¥2,869,500) without the account holders’ consent. The company will fully reimburse the fraudulently exchanged points.
Source: news.yahoo.co.jp / Original article here
What people said
Probably the former.
Ever since that story about some AI going rogue broke, this stuff's been happening way too often.
Re: #4
Whether it's an organization or some individual, they're probably just blasting indiscriminate attacks everywhere.
Say "sorry" and you get off scot-free.
Seriously, this.
They need to crack down hard on anyone who leaks data.
Otherwise no company's ever going to spend the money to beef up security.
So the consultants were all talk, huh?
Kind of like some famous karate master or something lol
So humans are already enslaved, huh lol
Something feels off.
Some points site I used also suddenly went into maintenance and shut down completely yesterday.
Probably a ton of indiscriminate attacks going around and everyone's panicking.
They're just piggybacking on the timing with their own announcement.
That way the bad impression gets diluted.
Did a war break out in cyberspace or something?
Seriously, the moment something convenient gets invented, someone shows up to abuse it.
Re: #64
Since it got publicized that AI can pull off unauthorized access on its own,
there's probably people out there going "now's my chance" and using AI for indiscriminate attacks.
Oh, they're already taking action — amending the law so leaking personal info isn't a problem anymore!
If you keep it all in one place and that account gets hit, you're done.
Well, it's not making headlines elsewhere right now, so you can probably guess what that means.
Re: #149
I've got my entire fortune parked at Mitsubishi UFJ, so I'm fine.
This kind of thing has been happening worldwide for ages.
In 2024, a healthcare service provider in the UK suffered a massive ransomware attack — thousands of surgeries, appointments, and tests across multiple hospitals and clinics were cancelled, and one death is believed to be linked to the resulting disruption.
Which screwup are you talking about?
They screwed up last year, remember?
Wasn't that one a phishing case?
I think the actual leak was at Rakuten Mobile.
Right.
It was still unauthorized access either way, and the response was so bad that the Financial Services Agency came down on them — which led the whole industry to set up a compensation system.
Other online brokerages followed suit too.
If you mess up yourself and get your password stolen,
there's nothing the company can do no matter how much security they put in place.
At that point the only option left is to block logins even when the correct password is entered.
Background and Key Points of This Story
Japan has no regulation that directly penalizes data leaks themselves — the Act on the Protection of Personal Information relies mainly on administrative guidance and recommendations, with nothing like the EU’s GDPR heavy fines. As a result, every time a leak happens, the same complaint — “the penalties are too light” — gets repeated, but no system designed to actually prevent recurrence has been put in place yet. It’s also easy to overlook that the announced figure of “up to 948,498 records” is simply the upper bound estimated at the time of the investigation, while confirmed fraudulent use was limited to 611 accounts totaling ¥2,869,500. The thread also included baseless accusations against China and other political comments, which this article does not adopt, as they are unsubstantiated speculation. Recently, in the case of unauthorized logins at Rakuten Securities, the Financial Services Agency issued administrative action and the industry moved to set up a compensation system — a similar response may be called for here as well.
*This article is excerpted and summarized from the 5ch (Breaking News+) thread “GMO’s ‘infoQ’ Hit by Unauthorized Access, Up to 950,000 Members’ Data Leaked — ¥2.87 Million in Points Fraudulently Exchanged“.

Leave a Reply