---
title: "GMO Research & AI Breach Hits 948,500 infoQ Members"
date: 2026-10-06
author: "Sofia Ramirez"
featured_image: "https://sqmagazine.co.uk/wp-content/uploads/2026/10/gmo-and-mrmax-data-breach.jpg"
categories:
  - name: "Cybersecurity"
    url: "/cybersecurity.md"
tags:
  - name: "News"
    url: "/tag/news.md"
---

# GMO Research & AI Breach Hits 948,500 infoQ Members

Attackers stole data on up to 948,500 members of GMO Research &amp; AI’s infoQ survey site, the Japanese firm said on 6th October, 2026. They also swapped members’ reward points for Amazon gift card codes.

## The Brief

- GMO Research &amp; AI said the stolen records include names, email and home addresses, phone numbers, and encrypted passwords.
- Attackers exchanged member points worth about 2.9 million yen ($18,000) for Amazon gift card codes, and the company will repay users in full.
- MrMax Holdings said a separate server intrusion may have exposed IDs, names, email addresses, and phone numbers for up to 1,735,154 members.
- Both companies said intruders abused the software running their services, and both detected the activity on the same Saturday.

## Hackers turned infoQ survey points into gift cards

GMO Research &amp; AI (TSE: 3695), the GMO Internet Group unit [formerly called GMO Research](https://gmo-research.ai/en/resources/news/notice-of-company-name-change), pays infoQ members in points for completing surveys. Those balances gave the intruders something to spend once they got in.

The intrusion started on 2nd October, 2026, a Friday, when hackers exploited a vulnerability in software the site uses. GMO detected it the next day, blocked the unauthorized access, and suspended infoQ. The company said a cybersecurity firm is helping with the investigation.

> 🚨Cyber Alert ‼️ 🇯🇵Japan – 𝗠𝗿𝗠𝗮𝘅 MrMax confirmed unauthorised access to servers supporting its app and online store. According to the company, up to 1,735,154 members may have been affected, with exposed data including member IDs, names, email addresses, and telephone numbers. Threat actor: Not specified Sector: Wholesale / Retail Data exposure (claimed): Up to 1,735,154 members Data type: Member IDs, names, email addresses, and telephone numbers Observed: Oct 6, 2026 Status: Confirmed ESIX©: 6.30 Full details and impact assessment on https://t.co/eB7qgxKFAa
> 
> — Hackmanac (@H4ckmanac) [October 6, 2026](https://x.com/H4ckmanac/status/2107349204859334671?ref_src=twsrc%5Etfw)

The stolen fields read like a starter kit for fraud: names, email and home addresses, phone numbers, and encrypted passwords. Contact details from a leak like this can resurface in later scams, a pattern laid out in [what happens to data after a breach](https://sqmagazine.co.uk/what-happens-data-breach/).

The points loss sets this case apart from a [typical data leak](https://sqmagazine.co.uk/data-breach-statistics/), because Amazon gift card codes carry cash value outside GMO’s own systems. GMO said it will fully reimburse affected users. Its disclosure, as reported, names neither the vulnerable software nor a CVE identifier. That leaves other administrators with no way to check whether they run the same component.

## MrMax puts 1,735,154 members on alert

**MrMax Holdings (TSE: 8203)**, a Fukuoka-based discount chain with stores across Kyushu, Kanto, and Chugoku, disclosed its own intrusion the same day. Staff spotted suspicious access to its app and online store servers on the evening of that Saturday. The retailer suspended services and blocked external access before the day was out.

A third party abused functions in the software behind the service to get in, the company said. Exposed fields cover IDs, names, email addresses, and phone numbers for app and online store members registered as of the detection date. Home addresses, birth dates, card details, passwords, and purchase history stayed out of reach.

“**We deeply apologize for the significant inconvenience and concern caused to our customers,**” MrMax said. The retailer had found no misuse when it published its notice but warned that phishing emails impersonating MrMax or related entities may follow.

The two disclosures extend a run of Japanese corporate incidents that includes [Asahi’s production-halting cyberattack](https://sqmagazine.co.uk/asahi-cyberattack-japan-production-halt/) last year. Yakiniku King operator Monogatari Corp. said a day earlier more than **10 million** pieces of customer information leaked via its reservation and rewards app. Daiwa Securities Group said data on around 110,000 customers may have been compromised through a contractor-operated server. Three of those four incidents ran through apps or sites that customers log into directly.

Neither GMO nor MrMax has filled in the technical gaps yet. GMO hasn’t said which software was vulnerable, how the attackers redeemed points tied to members’ accounts, or when infoQ will reopen. MrMax hasn’t said how its total splits between app users and online store shoppers.

## What’s Next?

infoQ members who reused their infoQ password on other sites should change it there first, since attackers now hold encrypted copies. MrMax members face a slower threat from [phishing email lures](https://sqmagazine.co.uk/phishing-email-statistics/) that use real names and phone numbers to look official.

Treating unsolicited MrMax emails and texts with suspicion, and skipping their links, helps reduce that risk. Until GMO names the vulnerable software, other operators of points-based platforms have nothing concrete to patch.