infoQ breach: loyalty points cashed out as Amazon gift cards
Attackers took 948,498 infoQ member records and turned 611 members' points into Amazon gift codes. Your loyalty points are cash. Guard redemption.
Attackers broke into infoQ, the survey-rewards site run by GMO Research & AI, and did two things. They copied up to 948,498 member records. Then they turned other people's reward points into Amazon gift codes. The data theft gets the headline. The loyalty points breach is the part every store with a rewards program should study, because points that convert to gift cards are cash with weaker locks.
What actually happened
GMO Research & AI published its notice on October 5. A third party used a software vulnerability in the platform to get in between October 2 and 3. The company stopped point exchanges at 11:24 a.m. on October 3, blocked the attack path at 2:15 p.m., and cut all outside access at 3:00 p.m. ITmedia reports the company found the problem after members contacted it.
The exposed fields: names, gender, birth dates, email and home addresses, phone numbers, member IDs, activity details, and encrypted passwords. infoQ did not store card numbers.
The money: 611 members had points exchanged for Amazon gift codes without consent, worth ¥2,869,500 (close to $20,000). GMO says it will pay all of it back.
The same weekend, discount retailer MrMax disclosed that someone abused a software function in its app and online store servers. Up to 1,735,154 members lost IDs, names, emails, and phone numbers. MrMax says no addresses, cards, passwords, or purchase history left, and it had seen no misuse at announcement time. Two consumer platforms, one weekend, the same pattern: the member database was the target.
Why loyalty points are your weakest payment rail
Your checkout has fraud scoring, 3-D Secure, and a processor watching every charge. Your points-redemption endpoint probably has a login and nothing else. That is the gap the infoQ attackers used. Gift codes are the perfect exit: instant, transferable, and spent before anyone checks a balance.
If your store, app, or service business runs points, credits, or store cash, do this:
- Put a delay on redemptions to gift cards or cash. A 24-hour hold kills the cash-out window.
- Rate-limit redemptions per account and across all accounts. A spike at 3 a.m. is an alert, not a sale.
- Ask for step-up auth (a one-time code or passkey) before points leave the system.
- Notify the member on every redemption. infoQ members found the theft before the company did.
- Build a kill switch that stops redemptions without taking the whole site down.
Key takeaways
- infoQ lost up to 948,498 member records through a software vulnerability
- 611 members had points cashed out as Amazon gift codes worth ¥2,869,500
- MrMax disclosed a separate breach of up to 1.73 million app and store members the same weekend
- Redemption endpoints need the same controls as checkout: holds, rate limits, step-up auth
- Build a redemption kill switch before you need one
Points are a currency. Treat the redemption flow like a payment flow. We build loyalty and store-credit systems with holds, rate limits, and alerts built in, on code you own. See what we build, or send us your rewards setup for a review.
Sources: GMO Research & AI notice, ITmedia on infoQ, ITmedia on MrMax.
- #loyalty-points
- #data-breach
- #account-takeover
- #ecommerce-security
- #japan
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
TikTok Buy Direct: one-click checkout outside TikTok Shop
TikTok Buy Direct adds one-click checkout from brands plus an AI Shopping Assistant, built with Shopify and Stripe. What your catalog data needs before it hits the feed.
Read itMeloni files to trademark her voice: AI voice cloning defense
Italy's prime minister filed an EU trademark for her voice to fight AI voice cloning. What a sound mark does, what it can't, and how to protect your brand voice.
Read it