On October 5, GMO Research & AI announced its survey panel infoQ was breached. Up to 948,498 members, the entire member base, may have lost email addresses, names, phone numbers and home addresses. You joined for the points. I run AliasFleet: one unique email address per site, so when the survey panel gets hit, the address in the stolen file belongs to the survey panel alone.
This one is different from most breaches I cover, because the attacker did not just take the data. They spent it.
What the file holds
| May have leaked | Not included |
|---|---|
| Name and kana | Credit card information (not stored) |
| Email address | My Number (not stored) |
| Phone number | |
| Address | |
| Date of birth and gender | |
| Password, encrypted | |
| Member ID, nickname, point balance, last survey date |
"May have leaked" is the company's own phrasing. The announcement says the attacker reached the member database and the personal information of all 948,498 members was taken out. There is no public breakdown of how much of it the attacker actually copied row by row, so treat the maximum as the working number.
The split that matters is what is in the file versus what is not. No payment details, no national ID numbers. But names, emails, phone numbers, addresses, dates of birth and encrypted passwords are the complete kit for impersonation. A phishing email that knows your name, your address and where you earn survey points does not look like phishing.
Two days of "emergency maintenance"
The timeline is short and sharp. The intrusion began sometime after October 2 through a vulnerability in software the company used on the site. On the morning of October 3, a member noticed something wrong with their points and reported it. That report is what started the investigation.
At 11:24 that morning, the company halted all point exchanges. At 2:15 p.m., it cut the attack path. At 3:00 p.m., it shut off external access to infoQ entirely. The site has been down since, showing visitors a notice about emergency maintenance. GMO has now admitted the shutdown was this incident all along. It also reported to Japan's Personal Information Protection Commission on October 5, the same day it went public, and started emailing members individually.
Why the quick detection matters
Credit where it is due: this is one of the faster breach timelines I have covered. Member report to full shutdown happened inside a single day. Compare that with breaches where weeks pass between intrusion and disclosure. GMO did not sit on this. The two days of maintenance theater before the announcement are a minor blemish; the containment speed is the real story.
The attacker already spent the loot
Here is the part that should make you sit up. In 611 accounts, the attacker converted the victim's points into Amazon gift codes, without the victim's knowledge. Total: 2,869,500 yen. GMO says it will fully compensate the stolen points.
This matters for two reasons. First, it proves intent and access in the same stroke. This was not a smash-and-grab where a database gets copied and dumped for sale later. Someone logged in as members, walked through the point-exchange flow, and cashed out in gift codes that are trivially resold or spent. That is monetization inside the service itself, which means the attacker understood the platform well enough to use it like a customer.
Second, it is a warning flare for every other loyalty and rewards account you own. Points, miles and credits sit in accounts people guard less carefully than bank logins, but they convert to real money in one click. If you reuse a password between a survey panel and something that pays out, the survey panel is now the weakest link in your financial chain.
If you are an infoQ member
- Change your infoQ password, and change every other account that shares it. GMO says the passwords were encrypted, but you do not know how well. Rotation is the only safe answer, and the company agrees.
- Expect impersonation. GMO is warning about emails, texts and calls that pretend to be the company or infoQ. Your real name, address and phone number are in the file, so expect the fakes to feel personal. Contact the company through its own site, never through a message that found you.
- Check your point balance and any Amazon gift-code redemptions you did not make. If points went missing, contact infoQ support through the official channel. GMO says unauthorized exchanges will be compensated in full.
- Turn on multifactor authentication on your email account. Your email address is in this file, and your inbox is the recovery path for everything else.
- Check Have I Been Pwned once the breach is listed. It is the canonical place to see which of your addresses have leaked and where.
The breach-response guide has the full checklist in order.
The survey-site bargain
Survey panels run on a particular bargain: a small reward for your attention, payable only to an account tied to your real identity. You cannot join anonymously and still get paid. So you hand over the real email, the real phone number, the real address, because the points need somewhere to land.
That bargain means the file GMO lost is not a side detail of the service. It is the service. Every member's identity row exists because the business model demands it. And the same bargain repeats across loyalty programs, cashback sites, coupon apps and every rewards scheme in Japan right now: Monogatari lost 10.79 million Yakiniku King member records on October 5, White Essence lost about 1.05 million account records the same week, and Daiki Suisan disclosed 174,933 app users a day earlier. The pattern is not a coincidence. Attackers are working down a list of member databases, and the ones that pay points are being cashed out as they go.
You cannot negotiate the bargain. What you can control is the address you hand over. Give every survey site, loyalty program and coupon app its own email alias. The next file that gets taken holds an address that belongs to that site alone: pause it and the phishing dies, rotate it and the spam has nowhere to go. The address itself names the source, which is the leak-tracing mechanism working exactly as designed.
If you have never used one: this is what an email alias is. The set-up guide takes about two minutes.
What I am watching for
Three open questions. First, which software had the vulnerability and whether other GMO group companies use it, because the same flaw rarely exists in only one place. Second, whether the 611 point-theft cases grow as members start checking balances, which would tell us how far the attacker got before the 11:24 halt. Third, whether the data surfaces anywhere public, which would turn this from a contained theft into a circulating file. If any of those break, this piece gets updated.
Top comments (0)