Security Guides
infoQ survey site breach (up to 948,498 records): what leaked and what members should do
Unauthorized access to infoQ, a Japanese survey site run by GMO Research & AI, exposed up to 948,498 members' names, birth dates, addresses, phone numbers and emails. 611 point exchanges were also fraudulent. What to do today.
For: people registered with infoQ, a Japanese survey site (including past registrants), and anyone who runs a points-based membership site. This article is based on the official notice from GMO Research & AI, Inc. and does not cover attack techniques.
What members should do today
Change the password on any service that shares your infoQ password
The company says passwords were encrypted, but as a precaution it recommends changing the password on any other service where you use the same one. The encryption method has not been disclosed.
Once an email and password pair is known, it may be tried on other sites. Start with email, online shopping and points services, and use a different password for each service. A password manager is the realistic way to do the inventory.
Turn on two-step verification for your email account
The email address you registered with infoQ is probably the password-reset address for many other services. If someone takes over that email account, they can reset passwords elsewhere too.
Major email services such as Gmail and Outlook offer two-step verification. Setup steps and how to choose a method are in Getting started with multi-factor authentication.
Do not open links in messages claiming to be infoQ or GMO
The company warns about suspicious emails, texts and calls posing as the company or infoQ. The company is itself emailing affected members individually from October 5, so genuine and fake messages will arrive at the same time.
If you receive a message about "point compensation procedures", "apology gift codes" or "identity verification", do not open the link; check the notices on the company's official website instead (see What is phishing?).
Never give account numbers, card numbers or passwords for compensation
The company says it will compensate fraudulently exchanged points in full, but the notice, as of October 6, does not describe the procedure.
A sender who knows your correct name, address and birth date is not proven genuine by that. Those are exactly the details that leaked. If someone asks for a bank account, card number or password in the name of compensation or a refund, check the procedure on the official website before doing anything.
Report point exchanges you did not make to the support center
infoQ has been suspended since October 3, so as of October 6 you may not be able to check your history. If you notice a point exchange you did not make, contact the infoQ Support Center listed by the company (infoq-support@gmo-research.ai; email accepted 24 hours, handled weekdays 10:00–18:00 Japan time).
Use the contact address on the company's official website, not one given in a message you received. When the service resumes, log in yourself and check your point balance and exchange history.
What not to do
Do not open an "infoQ login page" from a link in an email or text and enter your password. The service is suspended, so as of October 6 any message asking you to log in should be treated as suspicious first.
To check whether your email or password has appeared in past leaks, follow How to check if your password was leaked. Do not type the password itself into an unfamiliar site to check it.
What happened (from GMO Research & AI's notice)
GMO Research & AI, Inc. published its apology and notice on October 5, 2026. Everything below is as stated in the company's notice.
From Oct 2, 2026 (Fri)
Unauthorized access by a third party (found later in the investigation).Oct 3 (Sat), morning
After investigating an inquiry from a member, the company confirmed the unauthorized access.Oct 3, 11:24
Point exchanges stopped (Amazon gift codes and GMO Points).Oct 3, 14:15
The attack path was blocked.Oct 3, 15:00
Outside access to infoQ was cut off (service suspended). The suspended site had said "emergency maintenance"; the company says the suspension was due to this incident.Oct 5 (Mon)
Reported to the Personal Information Protection Commission. Apology and notice published; the company said it would email affected members individually, in turn.
- Scope
- Up to 948,498 records (as of Oct 5; every record of personal data the company holds)
- Items
- Name, name reading (furigana), gender, date of birth, email address, home address, phone number, password (encrypted), member ID, other registration data (nickname, point balance, usage information such as the date of the last survey answered)
- Not included
- The company does not hold credit card data or My Number
- Fraudulent exchanges
- 611 cases worth 2,869,500 yen were exchanged for Amazon gift codes without the members' consent. The company will compensate in full
- Cause
- A third party exploited a vulnerability in software used on the company's site to get in. The software and the vulnerability have not been named
- Investigation
- Continuing with the cooperation of a security firm
- Scope limits
- Business clients' data is not included, and no unauthorized access to the company's other services has been found
- Contact
- infoQ Support Center, infoq-support@gmo-research.ai (email accepted 24 hours, handled weekdays 10:00–18:00 Japan time)
What the leaked items can be used for in combination
Besides contact details (email, phone, address), this leak includes birth dates and encrypted passwords. Each combination calls for a different step.
Email + password (encrypted)
↓→
The same pair may be tried on other services
→ Change reused passwords; two-step verification on email
Name + email + phone number
↓→
Fake compensation or apology emails and texts with your correct name
→ Do not open links; check the official website's notices
Address + date of birth
↓→
Fake contact, including by post, that can answer identity questions
→ Knowing your birth date does not make a sender genuine
Not included, according to the company
- Credit card data (never held)
- My Number (never held)
- Business clients' data
- Other company services (no unauthorized access found)
Taken out
- Name, furigana, gender, date of birth
- Email, home address, phone number
- Password (encrypted)
- Member ID, nickname, point balance and more
How to read it: 'encrypted' does not mean 'no need to change'
The company says passwords were encrypted but has not disclosed the method. How hard it is to recover the original password depends heavily on how it was stored (the difference is explained in What is password hashing?).
The company itself recommends changing reused passwords as a precaution. If you stop reusing passwords, other services are protected whatever the method was.
For those who run points-based membership sites
What sets this incident apart is that, alongside the data being taken out, members' points were exchanged for external gift codes. Exchangeable points are close to money, for users and attackers alike. According to the notice, the company stopped point exchanges at 11:24 on October 3, the day it confirmed the unauthorized access. This section sticks to points that any service with a similar setup can review.
Record point exchanges per hour, by count and amount, and alert on the difference from normal
As a first step, record the hourly count and value of exchanges into gift codes or other companies' points, and notify someone when they pass several times the usual level.
Also cap how many exchanges one account and one source can make. Setting limits and alerting is covered in Rate limiting and abuse control.
Have a switch that stops only the exchange function
Being able to stop just the exchange function before taking the whole site down limits the damage sooner. Decide in advance who makes the call and how to switch it, and actually flip it once a year to confirm it works.
List the software your site runs and set update deadlines
The company attributes the cause to the exploitation of a vulnerability in software used on its site. The software has not been named, so this point is general.
List the products and libraries running on your site with their versions, and decide in advance which ones to update by when after a vulnerability is announced. How to prioritize is covered in CVE remediation playbook.
Sources (public record)
The facts in this article come from the public sources below. Undisclosed methods or details of the cause are not speculated on.
- GMO Research & AI, Inc., apology and notice regarding the leak of personal data from unauthorized access to its survey site infoQ (October 5, 2026, Japanese) — gmo-research.ai
- Nikkei, report that unauthorized access at a GMO group company leaked data on 950,000 people and points were misused (October 6, 2026, Japanese) — nikkei.com
Update history
2026-10-06: First version, based on GMO Research & AI's notice of October 5. The company says it will announce the investigation results and recurrence-prevention measures later; this article will be updated when they are published.
Read next
- Passwords: How to check if your password was leaked / Choosing a password manager
- Two-step verification: Getting started with multi-factor authentication
- Follow-on scams: What is phishing?
- Other Japanese incidents at the same time: The Yakiniku King app breach / Unauthorized access at Daiwa Securities' contractor
- Other 2026 incidents: list of breaches and cyberattacks (Japan and worldwide)
FAQ
QWhat leaked in the infoQ breach?
According to GMO Research & AI's notice of October 5, 2026, personal data for up to 948,498 records was taken out. The items are name, name reading (furigana), gender, date of birth, email address, home address, phone number, password (encrypted), member ID, and other registration data (nickname, point balance, and usage information such as the date of the last survey answered). The company says it does not hold credit card data or My Number (Japan's national ID number) in the first place.
QAm I affected?
The company describes the scope as every record of personal data it held as of October 5. If you have ever registered with infoQ, it is realistic to act as if you are affected. The company says it is emailing affected members individually, in turn, from October 5.
QShould I change my password?
The company says passwords were encrypted, but as a precaution it recommends changing the password on any other service where you use the same password as infoQ. infoQ itself was suspended as of October 6, so change your infoQ password after checking the company's instructions when the service resumes.
QWhat happens if my points were exchanged without my consent?
According to the notice, points in 611 cases worth 2,869,500 yen were exchanged for Amazon gift codes without the members' consent, and the company will compensate the fraudulently exchanged points in full. If you notice an exchange you did not make, the company asks you to contact the infoQ Support Center (infoq-support@gmo-research.ai). The notice, as of October 6, does not describe the compensation procedure.
QWhat scams should I watch for?
The company warns about suspicious emails, texts and calls posing as the company or infoQ. Because names, birth dates, addresses, phone numbers and emails leaked together, fake messages with correct personal details are possible. Do not give bank account numbers, card numbers or passwords to anyone contacting you about compensation or an apology; check the notices on the company's official website instead.
QWhat caused the breach?
The company says it confirmed that a third party exploited a vulnerability in software used on its site to get in. It has not said which software or what kind of vulnerability. It is continuing the investigation with a security firm and says it will announce the results and measures to prevent a recurrence later.