GMO Payment Gateway, Inc.
June 1, 2026
We have experienced a disruption in the payment services we provide.
We deeply apologize for the great inconvenience caused to our customers and all related parties.
Furthermore, as confirmed by our company, there has been no unauthorized intrusion into the system or information leakage regarding this issue.
Record
1. Occurrence
During the following period, there were situations where it was difficult to use multiple of our payment services, including the PG Multi-Payment Service.
|
Date and Time |
scope of influence |
|
May 27, 2026 (Wed) 12:07 ~ 13:11 |
PG Multi-Payment Service part of the payment transaction using OpenAPI type (*1) |
|
May 28, 2026 (Thu) 11:35 ~ 11:51 / 12:14 ~ 12:23 |
PG Multi-Payment Service part of the payment transaction using OpenAPI type (*1) |
|
May 30, 2026 (Sat) 11:59–13:22 |
Part of the transaction involving multiple of our payment services, including PG Multi-Payment Service |
|
May 30, 2026 (Sat) 13:51 ~ 14:01 / 14:07 ~ 14:17 |
PG Multi-Payment Service part of the payment transaction using OpenAPI type (*1) |
(※1)OpenAPI Type: One of the connection methods in PG Multi-Payment Service, connecting the merchant's system via API.
2. Causes
A large number of abnormal requests originating from the systems of specific merchants reached our company's system, causing processing delays during the above time period due to exceeding the maximum number of simultaneous connections and the activation of the DDoS detection function (*2).
Furthermore, as confirmed by our company, there has been no unauthorized intrusion into the system or information leakage regarding this issue.
(※2)DDoS detection function: A mechanism that automatically detects and defends against attacks (DDoS attacks) that attempt to disrupt services by sending large volumes of external communication.
3. Current Situation
We have implemented necessary measures such as tuning the DDoS detection function (optimizing operation settings), improving the maximum number of simultaneous connections, and adding connection restrictions for abnormal requests, and the system is currently operating normally.
Once again, we deeply apologize for the great inconvenience caused to our customers and all stakeholders.