Japan Cyberattacks Expose Millions of Customer Records

Several Japanese companies have disclosed separate unauthorized-access incidents affecting customer information in recent days. The affected organizations include GMO Research & AI, Mr Max Holdings, Monogatari Corporation, which operates Yakiniku King, and Daiwa Securities.

The incidents span survey services, retail, restaurants and financial services. While they occurred within a short period, available evidence does not establish that they were carried out by the same attacker or as one coordinated campaign.

GMO Research & AI Confirms 948,498 Records Exposed

GMO Research & AI confirmed unauthorized access to the server supporting its infoQ survey service. The company said an attacker exploited a vulnerability in software used by the site. GMOリサーチ&AI

The company reported that information covering up to 948,498 records was taken outside its systems. The exposed information includes names, gender, dates of birth, email addresses, addresses, telephone numbers, member IDs and encrypted passwords. Credit-card and My Number information were not held by the service. GMOリサーチ&AI

The breach also resulted in direct financial loss for some members. Points belonging to 611 members, worth ¥2,869,500, were exchanged without authorization for Amazon gift codes. GMO said it would fully compensate the affected points and has suspended infoQ while its investigation continues. GMOリサーチ&AI

Mr Max Says Up to 1.7 Million Customers May Be Affected

Retailer Mr Max Holdings reported unauthorized access to servers supporting its app and online store on October 3.

The company said up to 1,735,154 registered customers could be affected. Potentially exposed information includes member IDs, names, email addresses and telephone numbers. Mr Max said addresses, dates of birth, credit-card information, passwords and purchase histories were not leaked. 総合ディスカウントストア ミスターマックス

As of its October 6 notice, the company had not confirmed misuse of the leaked information. It warned customers, however, that the exposed data could be used in impersonation or phishing messages. 総合ディスカウントストア ミスターマックス

Yakiniku King and Daiwa Securities Report Additional Data Exposure

Monogatari Corporation, operator of Yakiniku King, confirmed unauthorized access to the restaurant chain’s official app member-management system.

The company said 10,788,963 records were leaked from 10,808,784 registered records. The exposed information includes member numbers, registered names, email addresses and telephone numbers. Passwords, birth dates, gender, postal codes and store-use history were not leaked, according to the company. 物語コーポレーション

Daiwa Securities separately said information involving as many as 110,000 customers may have been leaked after unauthorized access to servers operated by external vendor Scala Communications. The information included names and account numbers, while the broader incident involved about 220,000 records. Daiwa said its own systems were not breached and the leaked information could not be used to access securities accounts or conduct online trading. The Japan Times

Company Affected service Potential scope Information reported as exposed
GMO Research & AI infoQ 948,498 records Names, contact details, addresses, encrypted passwords and other membership data
Mr Max App and online store 1,735,154 customers Member IDs, names, email addresses, phone numbers
Monogatari Yakiniku King app 10,788,963 records Member numbers, names, email addresses, phone numbers
Daiwa Securities External vendor server ~110,000 customers Names, email addresses and account numbers

Figures reflect company disclosures and reporting available as of October 6, 2026.

What Customers Should Watch For

The immediate concern for affected customers is potential phishing and impersonation using leaked contact information. Mr Max and GMO have specifically warned users to be cautious about suspicious emails, SMS messages and phone calls. GMOリサーチ&AI

Customers should avoid clicking unexpected links or attachments and should not provide passwords, payment information or security codes in response to unsolicited messages.

What Readers Should Know

  • Millions of customer records have been exposed across several separate Japanese incidents, with the Yakiniku King breach alone involving more than 10.7 million records.
  • The practical risk extends beyond the original breach: leaked contact information can make phishing and impersonation attempts more convincing.
  • The investigations are still developing: the responsible attackers and detailed entry methods for several incidents have not been publicly established.

Conclusion

The incidents involving GMO Research & AI, Mr Max, Monogatari and Daiwa Securities demonstrate how unauthorized access can expose large volumes of customer information across very different industries.

The available evidence does not currently show that these breaches form one coordinated attack. For affected customers, the more immediate priority is to watch for suspicious communications and follow security instructions issued by the companies involved.

Sources and Further Reading

Leave a Reply

Your email address will not be published. Required fields are marked *

You May Also Like
Singapore Launches AI Workforce Plan for 80,000 Finance Workers by 2028

Singapore Launches AI Workforce Plan for 80,000 Finance Workers by 2028

Singapore’s financial sector has launched an initiative to prepare more than 80,000…
Trump Calls AI Super Intelligence as US Rejects Global Rules

Trump Calls AI ‘Super Intelligence’ as US Rejects Global AI Rules

The United States is changing how it refers to artificial intelligence in…
GPT-6 Sol and Luna: OpenAI's Lower-Cost AI Models Explained

GPT-6 Sol and Luna: OpenAI’s Lower-Cost AI Models Explained

OpenAI has expanded its GPT-6 family with GPT-6 Sol and GPT-6 Luna,…