Several Japanese companies have disclosed separate unauthorized-access incidents affecting customer information in recent days. The affected organizations include GMO Research & AI, Mr Max Holdings, Monogatari Corporation, which operates Yakiniku King, and Daiwa Securities.
The incidents span survey services, retail, restaurants and financial services. While they occurred within a short period, available evidence does not establish that they were carried out by the same attacker or as one coordinated campaign.
GMO Research & AI Confirms 948,498 Records Exposed
GMO Research & AI confirmed unauthorized access to the server supporting its infoQ survey service. The company said an attacker exploited a vulnerability in software used by the site. GMOリサーチ&AI
The company reported that information covering up to 948,498 records was taken outside its systems. The exposed information includes names, gender, dates of birth, email addresses, addresses, telephone numbers, member IDs and encrypted passwords. Credit-card and My Number information were not held by the service. GMOリサーチ&AI
The breach also resulted in direct financial loss for some members. Points belonging to 611 members, worth ¥2,869,500, were exchanged without authorization for Amazon gift codes. GMO said it would fully compensate the affected points and has suspended infoQ while its investigation continues. GMOリサーチ&AI
Mr Max Says Up to 1.7 Million Customers May Be Affected
Retailer Mr Max Holdings reported unauthorized access to servers supporting its app and online store on October 3.
The company said up to 1,735,154 registered customers could be affected. Potentially exposed information includes member IDs, names, email addresses and telephone numbers. Mr Max said addresses, dates of birth, credit-card information, passwords and purchase histories were not leaked. 総合ディスカウントストア ミスターマックス
As of its October 6 notice, the company had not confirmed misuse of the leaked information. It warned customers, however, that the exposed data could be used in impersonation or phishing messages. 総合ディスカウントストア ミスターマックス
Yakiniku King and Daiwa Securities Report Additional Data Exposure
Monogatari Corporation, operator of Yakiniku King, confirmed unauthorized access to the restaurant chain’s official app member-management system.
The company said 10,788,963 records were leaked from 10,808,784 registered records. The exposed information includes member numbers, registered names, email addresses and telephone numbers. Passwords, birth dates, gender, postal codes and store-use history were not leaked, according to the company. 物語コーポレーション
Daiwa Securities separately said information involving as many as 110,000 customers may have been leaked after unauthorized access to servers operated by external vendor Scala Communications. The information included names and account numbers, while the broader incident involved about 220,000 records. Daiwa said its own systems were not breached and the leaked information could not be used to access securities accounts or conduct online trading. The Japan Times
| Company | Affected service | Potential scope | Information reported as exposed |
|---|---|---|---|
| GMO Research & AI | infoQ | 948,498 records | Names, contact details, addresses, encrypted passwords and other membership data |
| Mr Max | App and online store | 1,735,154 customers | Member IDs, names, email addresses, phone numbers |
| Monogatari | Yakiniku King app | 10,788,963 records | Member numbers, names, email addresses, phone numbers |
| Daiwa Securities | External vendor server | ~110,000 customers | Names, email addresses and account numbers |
Figures reflect company disclosures and reporting available as of October 6, 2026.
What Customers Should Watch For
The immediate concern for affected customers is potential phishing and impersonation using leaked contact information. Mr Max and GMO have specifically warned users to be cautious about suspicious emails, SMS messages and phone calls. GMOリサーチ&AI
Customers should avoid clicking unexpected links or attachments and should not provide passwords, payment information or security codes in response to unsolicited messages.
What Readers Should Know
- Millions of customer records have been exposed across several separate Japanese incidents, with the Yakiniku King breach alone involving more than 10.7 million records.
- The practical risk extends beyond the original breach: leaked contact information can make phishing and impersonation attempts more convincing.
- The investigations are still developing: the responsible attackers and detailed entry methods for several incidents have not been publicly established.
Conclusion
The incidents involving GMO Research & AI, Mr Max, Monogatari and Daiwa Securities demonstrate how unauthorized access can expose large volumes of customer information across very different industries.
The available evidence does not currently show that these breaches form one coordinated attack. For affected customers, the more immediate priority is to watch for suspicious communications and follow security instructions issued by the companies involved.