TOKYO - More Japanese companies, including the maker of Citizen watches, reported Tuesday unauthorized access to servers and possible leaks of personal information, with the Japanese government describing the situation as "serious."

GMO Research & AI Inc., a subsidiary of GMO Internet Group Inc., has said up to around 948,500 records of members of its infoQ survey website have been stolen, including members' names, email addresses, home addresses, phone numbers and encrypted passwords.

Mr Max Holdings Ltd. said Tuesday customer information had been leaked from a server used for its app and online store, potentially affecting up to 1.7 million customers by exposing names, email addresses and phone numbers, but not credit card information, home addresses or birth dates.

Citizen Watch Co. said information on about 100,000 customers may have leaked due to unauthorized access to a server operated by a contracted company. The data could include names, addresses, telephone and credit card numbers as well as bank accounts.

The revelations follow similar cases that have come to light in recent days.

"We take (the revelations) very seriously," Chief Cabinet Secretary Minoru Kihara said at a press conference, adding that the government will gather information to assess the extent of the damage quickly.

GMO Research & AI also said some members' rewards, worth about 2.9 million yen ($18,000), were illicitly exchanged for Amazon gift card codes.

Members earn points by completing surveys on GMO Research and AI's infoQ website. The firm said it will reimburse those affected for the full value of points fraudulently exchanged and that it is contacting users individually to urge them to change their passwords.

The attack began last Friday, and the company blocked the unauthorized access and suspended the service once it became aware of the incident the following day.

The hackers exploited a vulnerability in software used by the site, the company said, adding that an investigation is continuing with help from a cybersecurity firm.

Mr Max said it detected the unauthorized access late Saturday afternoon and immediately suspended the services.

Potentially affected were customers who were registered with its app or online store as of Saturday.

"We sincerely apologize for the inconvenience and concern we have caused our customers," the retailer said in a statement.

Mr Max said it had found no evidence that the leaked information had been misused so far but urged customers to watch out for phishing emails.

There has been a spate of announcements by firms reporting data breaches and leaks.

Monogatari Corp., which runs the Yakiniku King barbecue chain, said Monday that more than 10 million pieces of customer information, covering almost its entire registered user base, were leaked following unauthorized access to the system supporting its app for making reservations and earning rewards.

Meanwhile, some 1.6 million images of the driver's licenses of current and former members of the "Times Car" car-sharing service were leaked, while delivery firms Yamato Transport Co. and Sagawa Express Co. said that customer names, addresses, and other information may have been leaked.

File photo taken in January 2024 shows GMO Internet Group Inc.'s cybersecurity center in Tokyo. (Kyodo)
Related coverage: