GMO Subsidiary Leaks Data of 940,000 Members, 2.86 Million Yen in Points Stolen

時事通信··JP·Read original
3▲0 ▼0Impact / 5
Summary · why it matters

A wave of unauthorized access targeting companies has led to a series of personal data leaks, and at a subsidiary of GMO Internet Group, secondary damage was also confirmed in which members' points were fraudulently exchanged. GMO Research & AI announced that its survey site infoQ suffered unauthorized access, leaking the names, phone numbers and other data of 948,498 registered members, and it was found that points totaling 2.86 million yen belonging to some members had been exchanged for Amazon gift codes; the company will compensate the full amount. Mr. Max Holdings, which operates discount stores, also disclosed on the 6th that the phone numbers, email addresses and other data of up to 1,735,154 members of its store-operating company's app and online store had leaked. In addition, Daiwa Securities said data on about 110,000 customers may have been compromised, and Citizen Watch said data on about 100,000 customers may have leaked, among other incidents, with cyberattacks showing no sign of letting up. It has also been pointed out that the spread of artificial intelligence is casting a shadow as a background factor behind the surge.

Theme Impact 1

Related news

Thailand
▲3

SAMTEL says subsidiary SCI wins IEAT cyber center contract worth 146.20 million baht

Samart Telcoms Public Company Limited, or SAMTEL, disclosed that Secure Info Company Limited, or SCI, a subsidiary in which the company holds a 99.99% indirect stake through Samart Comtech Company Limited, signed a purchase and sale contract for the procurement of machinery and equipment for the project to establish a cyber operations center and a data backup center, or Digital Resilience Center, at the SMART PARK Industrial Estate office with the Industrial Estate Authority of Thailand on September 29, 2026. The total project value is 146.20 million baht, including value-added tax, with delivery scheduled for completion by April 27, 2027. Payment terms are divided into five installments based on completed work progress.
About megatrends
Cybersecurity & Digital Trust › Cyber Resilience & Ransomware Recovery ▲Demand
SAMTEL.BK · Demand · Positive SAMTEL's 99.99%-owned subsidiary SCI won a 146.20 million baht IEAT contract for a cyber operations and data backup center.
Samart Comtech Co., Ltd. · Demand · Positive Samart Comtech's subsidiary SCI signed the 146.20 million baht IEAT Digital Resilience Center procurement contract.
Read original ↗
InfoQuest·2hRead more →
Japan
▲3

Unauthorized Access Hits SoftBank Subsidiary IDC Frontier, Municipal and Corporate Websites Unreachable

IDC Frontier, a SoftBank subsidiary that provides cloud services, announced on the 7th that it suffered unauthorized access by a third party, causing an outage in its IDCF Cloud service for municipalities and businesses. The outage occurred around 3:40 a.m. that day, leaving some services unavailable. The company said it received an external ransomware attack, and the cloud management platform automatically executed a shutdown. The company has not disclosed details of its service customers, but numerous websites, including those of Ibaraki Prefecture, the city of Kodaira in Tokyo, Jiji Press, and Tobu Zoo, became impossible to view or update. To prevent secondary damage and data leaks, the company has cut off its network and is working to identify the detailed intrusion route while rushing to set up an alternative environment.
About megatrends
Cybersecurity & Digital Trust › Cloud & Workload Security ▼Technology
Cloud & Digital Infrastructure › Specialized / Developer & Managed-Hosting Cloud ▼Technology
Cybersecurity & Digital Trust › Cyber Resilience & Ransomware Recovery ▲Technology
IDC Frontier Inc. · Regulation · Negative IDC Frontier itself suffered the unauthorized access and ransomware attack, forcing a network shutdown and service outage.
9434.JP · Regulation · Negative Its subsidiary IDC Frontier was hit by unauthorized access and ransomware, creating regulatory/legal exposure for SoftBank Corp.
9984.JP · Regulation · Negative Subsidiary IDC Frontier suffered a ransomware/unauthorized-access breach, exposing SoftBank Group to legal and regulatory fallout.
Read original ↗
時事通信·4hRead more →
South Korea
▲

Major South Korean churches investigate cyberattack, risking leak of 850,000 members' data

Two large Christian churches in South Korea are rushing to investigate a cyberattack after personal data of many members was found on overseas servers. Oasis Security disclosed that it found member data, account information, and attack logs linked to Yoido Full Gospel Church and Sarang Church in Seoul. Yoido Full Gospel Church said today that a preliminary review found data of as many as 850,000 members may have leaked, mostly names and dates of birth, while a smaller portion included records of changes to resident registration numbers, addresses, and phone numbers. The church has notified potentially affected members, suspended external access to its servers, and changed passwords to prevent further leaks. Sarang Church said it has set up a task force to investigate the attack and has notified the relevant authorities. Oasis Security said some evidence points to the use of AI tools, including references to sub-agents, as well as numerous attack reports that appear to have been generated by automated systems. The attack comes as South Korea faces a wave of cyberattacks; previously, several commercial banks were hacked, causing customer personal data to leak. President Lee Jae-myung said on Tuesday that he believes AI may have been used in the attacks on those banks.
About megatrends
Cybersecurity & Digital Trust › Data Security & Cyber Resilience ▲Technology
Oasis Security · · Neutral Oasis Security disclosed it found the leaked member data and attack logs, but the article does not state any business impact on the firm.
Read original ↗
InfoQuest·7hRead more →
Japan
▼

Times Car kept ID documents for 7 years, widening breach damage

At the car-sharing service Times Car, roughly 6.6 million members' records from the past seven years, including those of former members, were leaked, and of these, about 1.6 million involved identity verification documents. According to parent company Park24, which operates the service, former members' information such as addresses and names was retained for seven years in line with the Corporate Tax Act, while identity verification documents were kept for seven years on the company's own judgment in order to handle inquiries and similar matters. Professor Ichiro Sato of the National Institute of Informatics pointed out that the documents should have been deleted at the time identity verification was performed, and criticized the handling as sloppy, saying they should have been stored so that they could not be accessed from outside. Yuji Kakeya, principal of the Security Research Center at Macnica, which works on cybersecurity measures, expressed concern that highly accurate personal information, such as that backed by official documents, may sell for a higher price. Experts stress that management should issue a directive and review their companies' data management.
About megatrends
Cybersecurity & Digital Trust › Data Security Posture & DLP ▼Regulation
Cybersecurity & Digital Trust › Data Security & Cyber Resilience ▼Regulation
4666.JP · Regulation · Negative Parent of Times Car; 6.6 million members' records leaked, including 1.6 million ID documents kept seven years, drawing expert criticism of sloppy data handling.
Read original ↗
時事通信·14hRead more →
United KingdomUnited States
2

ASOS Shares Fall 9% After Hackers Claim Customer Data Breach

ASOS shares fell as much as 13.2% before paring losses to trade around 9% lower on Tuesday, after customers received a notification through the online fashion retailer's app claiming that hackers had compromised its data. The message, addressed to ASOS' data protection officer and IT staff, said, "We have fully compromised the Snowflake instance. Engage with us, or we will leak it." ASOS has not commented on the notification, leaving it unclear whether any customer data was accessed or compromised. The message included a link to a Telegram channel called the Xuanye group gateway, and cybersecurity firm Sophos said it had not previously encountered the group and that it did not appear on the Telegram channels or forums it monitors. Snowflake is a cloud platform used to store and analyse data, hosting Simon AI, which combines customers' behavioural, transactional and demographic information into individual profiles. Nearly 500 customers reported problems with the ASOS website shortly before 10 am, according to Downdetector, though the website and app appeared to be functioning normally until 9:41 am and it was unclear whether the reported issues were related to the notification.
About megatrends
Cybersecurity & Digital Trust › Data Security & Cyber Resilience Capital
SNOW · Regulation · Neutral Hackers claim to have compromised an ASOS Snowflake instance, but it is unclear whether any data was accessed and no Snowflake-specific breach is confirmed.
Read original ↗
Investing.com·1dRead more →
South Korea
▲2impact 4

South Korean Leader Says AI Signals Found in Major Bank Hacks, Orders Swift Probe

South Korean President Lee Jae-myung revealed on Tuesday, October 6, 2026, that there are signs artificial intelligence, or AI, may have been used in cyberattacks on several banks in the country, and called on South Korea to speed up development of cybersecurity systems suited to the AI era. Speaking during a cabinet meeting, he said that in some hacking cases traces of AI use have begun to emerge, which has caused considerable public concern, and ordered relevant agencies to swiftly establish the facts clearly, while mobilizing personnel and resources to minimize damage. South Korean police have launched a full-scale investigation after several commercial banks were hit by cyberattacks that led to the leakage of customers' personal data. The Financial Services Commission, or FSC, disclosed that Shinhan Bank and KB Kookmin Bank, as well as other financial institutions, reported being hit by cyberattacks, while Hana Bank and Woori Bank also faced data leakage incidents. The Financial Supervisory Service, or FSS, and the Financial Security Institute passed on information about 28 suspicious IP addresses, as well as some country data linked to the latest cyberattack attempts, to the financial sector for further checks and prevention. However, South Korean authorities have not yet disclosed what type of AI tools the attackers used, and there are still no details about the full scope of damage from the incidents.
About megatrends
Cybersecurity & Digital Trust › Cyber Resilience & Ransomware Recovery ▲Regulation
105560.KO · Regulation · Negative KB Kookmin Bank was among the South Korean banks hit by AI-linked cyberattacks that leaked customer personal data, triggering a police and FSC investigation.
Read original ↗
Money & Banking·1dRead more →