← Incident database

gmo-infoq-2026 · Disclosed 2026-10-05

infoQ: software vulnerability exploited, with unauthorized point redemptions

GMO confirmed information theft through a software vulnerability, affecting up to 948,498 records, plus unauthorized point redemption in 611 cases.

Cause unresolved / undisclosed

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    A site software vulnerability was exploited; product and patch timing are undisclosed.

    [s1]5. 原因
  • Reported fact

    Potential scope is up to 948,498 records. Unauthorized point redemptions involved 611 cases and ¥2,869,500.

    [s1]3. 対象となる情報 / 4. ポイントの不正な交換

Timeline

  1. Investigation found access from this date onward. [s1]

  2. Customer reports prompted investigation and suspension of redemption and the service. [s1]

  3. Impact disclosed and reported to the privacy regulator. [s1]

Reported response

  • Reported fact

    The path and external access were blocked; specialists continue investigating. Reimbursement was announced.

    [s1]4. ポイントの不正な交換 / 6. 当社の対応

Evidence relevant to prevention

Insufficient evidence

Inspect deployed versions, advisories, access privileges and logs, and redemption authorization and limits.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The reviewed disclosures do not establish attacker use of AI.

Patch neglect versus pre-disclosure exploitation is unresolved. Do not add the 611 cases to the overall scope.

Sources

  1. [s1] GMOリサーチ&AI · Primary source

    infoQへの不正アクセスによる個人情報漏えいに関するお知らせ ↗

    Published 2026-10-05 · Reviewed 2026-10-09