Cyber & AI intelligence
Wasteland.
Briefs indexed3016
Issues31
Published Mondays07:30 CT
▣ Breach JAPANESE-RESTAURAN 2026-10-05

Monogatari Corp: Yakiniku King App Breach Exposes 10.79M Members

"Monogatari Corporation (TSE: 3097) runs the Yakiniku King barbecue restaurant chain. The company says an outside party got into the member management system behind the chain's official reservation and rewards app and…"

Monogatari Corporation (TSE: 3097) runs the Yakiniku King barbecue restaurant chain. The company says an outside party got into the member management system behind the chain's official reservation and rewards app and took personal data on almost every registered user. Kyodo News, reported via Anadolu Agency, put the number at "more than 10 million customers." Reports based on the company's October 5 disclosure give the exact figure: BigGo Finance reports 10,788,963 leaked records out of 10,808,784 registered users, and TipRanks puts it at about 10.79 million of about 10.81 million. The figures agree. Note that we have not reviewed Monogatari's own filing directly. Every account here comes from secondary reporting of it. No threat actor has claimed the attack, and no one has publicly linked it to a known group.

A brokerage incident was reported alongside this one, with about 110,000 clients possibly affected. Anadolu Agency names that brokerage as Daiwa Securities, so it is the incident we have already covered. This brief does not cover it.

What Happened

All the accounts agree on the timeline:

According to TipRanks, the company reported the incident to regulators and police and is investigating the cause with the app's system developers. TipRanks also reports that Monogatari confirmed its other brand apps were not affected. The Yakiniku King app is still running with extra security and monitoring. Monogatari says it is still assessing the financial impact on the group.

Every source says there is no evidence yet that the data has been published or misused. The company has not said how the attacker got in, and the investigation is ongoing.

What Was Taken

The company lists four confirmed data fields:

BigGo and TipRanks both report that the following were not taken: login passwords, dates of birth, gender, postal codes, store visit history and loyalty points. Monogatari says it does not store payment card data, so no card details were at risk.

Each record on its own is fairly low in sensitivity. The concern is the scale. Almost the whole member base was taken, about 10.8 million people, and each record ties a real name to a verified email address and phone number for a known brand. That combination is exactly what convincing phishing and smishing need.

Why It Matters

This breach is the latest in a run of Japanese consumer and hospitality incidents in 2026 where stolen customer data has quickly been turned into targeted phishing. The incidents below are separate from the Monogatari breach, and no source links them to it:

The pattern is the same each time. Attackers take contact data plus real transaction or membership details, then use those details to make phishing messages look genuine. A message that quotes your real Yakiniku King membership number will look credible to most recipients. Defenders should expect impersonation campaigns using the Monogatari data, even though none has been reported yet.

The Attack Technique

Unknown. Monogatari has not disclosed how the attacker got in, and its investigation with the system developers is ongoing. The available facts are:

The source set includes SentinelOne's entry for CVE-2026-94041. It describes an authenticated SQL injection in admin/add_menu.php of the open-source AdithyaYelloju Restaurant-Management-System, published to NVD on September 20, with a public exploit and no fix available. None of the sources connect this CVE to Monogatari, and nothing suggests that Monogatari uses that project. It is included here only as a reminder that injection flaws in restaurant software admin panels are being found and exploited. It should not be read as the cause of this breach.

What Organizations Should Do

  1. Audit app and loyalty back ends as crown-jewel systems. Member management databases holding millions of records need the same access control, query logging and alerts on bulk exports as financial systems. Alert on unusually large result sets or sustained enumeration.
  2. Harden admin interfaces against injection. Use parameterized queries everywhere, put admin panels behind VPN or zero-trust access, and require MFA for every admin account. IMADEYA's response included cutting admin privileges, rotating all admin passwords and enforcing two-factor authentication.
  3. Review third-party and SaaS integrations. The TEMAIRAZU and IMADEYA cases show that a site controller or linked commerce service can be the point where data leaks. List every system that can read customer data, and tighten each one's permissions.
  4. Warn customers before the phishing starts. Tell members which channels and domains you actually use (IMADEYA published its official domain), say plainly that you will never ask for card details by message, and explain that a message quoting real account details is not proof it is genuine.
  5. Watch for brand impersonation. Look for lookalike domains, fake app listings and SMS sender IDs that impersonate your brand. Monitor leak sites and forums for your dataset, and have takedown processes ready.
  6. Notify regulators and police early. Monogatari, Temairazu and IMADEYA all reported to Japan's Personal Information Protection Commission and/or police, which is the baseline expected under Japan's privacy law.

Sources: Data of over 10M customers exposed in cyberattacks on Japanese firms | CVE-2026-94041: Restaurant Management System SQL Injection | Unauthorized Access Hits Yakiniku King App in Japan, 10.79 Million... | 【Important Notice】Regarding Potential Leakage of Customer Informati... | お客様情報の外部流出の可能性に関するお詫びとお知らせ(第1報) 株式会社いまでやのプレスリリース | Monogatari Corp Probes Major Data Leak at Yakiniku King App | Important News Regarding the Leak of Customer Information Hotel Gr... | 手間いらず「TEMAIRAZU」に不正アクセス 宿泊者情報が閲覧・取得された可能性、WhatsAppなどで不審メッセージセキュリティニ...