Monogatari Corporation (TSE: 3097) runs the Yakiniku King barbecue restaurant chain. The company says an outside party got into the member management system behind the chain's official reservation and rewards app and took personal data on almost every registered user. Kyodo News, reported via Anadolu Agency, put the number at "more than 10 million customers." Reports based on the company's October 5 disclosure give the exact figure: BigGo Finance reports 10,788,963 leaked records out of 10,808,784 registered users, and TipRanks puts it at about 10.79 million of about 10.81 million. The figures agree. Note that we have not reviewed Monogatari's own filing directly. Every account here comes from secondary reporting of it. No threat actor has claimed the attack, and no one has publicly linked it to a known group.
A brokerage incident was reported alongside this one, with about 110,000 clients possibly affected. Anadolu Agency names that brokerage as Daiwa Securities, so it is the incident we have already covered. This brief does not cover it.
What Happened
All the accounts agree on the timeline:
- October 2 (Friday): Monogatari detected unauthorized access to the app's member management system. BigGo reports that the company cut off the attacker's connections and added defensive measures right away.
- October 3: The company confirmed that member data had been taken.
- October 5: Monogatari disclosed the breach publicly.
According to TipRanks, the company reported the incident to regulators and police and is investigating the cause with the app's system developers. TipRanks also reports that Monogatari confirmed its other brand apps were not affected. The Yakiniku King app is still running with extra security and monitoring. Monogatari says it is still assessing the financial impact on the group.
Every source says there is no evidence yet that the data has been published or misused. The company has not said how the attacker got in, and the investigation is ongoing.
What Was Taken
The company lists four confirmed data fields:
- Membership numbers
- Names (as registered in the app)
- Email addresses
- Phone numbers
BigGo and TipRanks both report that the following were not taken: login passwords, dates of birth, gender, postal codes, store visit history and loyalty points. Monogatari says it does not store payment card data, so no card details were at risk.
Each record on its own is fairly low in sensitivity. The concern is the scale. Almost the whole member base was taken, about 10.8 million people, and each record ties a real name to a verified email address and phone number for a known brand. That combination is exactly what convincing phishing and smishing need.
Why It Matters
This breach is the latest in a run of Japanese consumer and hospitality incidents in 2026 where stolen customer data has quickly been turned into targeted phishing. The incidents below are separate from the Monogatari breach, and no source links them to it:
- TEMAIRAZU (hotel site controller): Temairazu, Inc. disclosed unauthorized access to its TEMAIRAZU reservation management system on September 28. A report by Security Measures Lab (Rocket Boys) says that from late on September 21, guests at several hotels received messages over WhatsApp, WeChat, email and SMS. The messages referred to their real reservations and pushed them to re-enter card details or make urgent payments. Fujita Kanko, which runs Hotel Chinzanso Tokyo, the HOTEL TAVINOS properties and Washington Hotel franchises, confirmed that its guests were affected. Temairazu has said only that it "cannot rule out" that guest data was viewed or taken, and the link between the intrusion and the messages is still under investigation.
- IMADEYA (wine and liquor retailer): In August, IMADEYA disclosed that about 30 customers had received phishing emails containing their correct names, order numbers and order amounts. Two customers entered card details on the phishing site. The cause, including possible compromise of linked services such as Shopify, Smaregi and CROSS MALL, was still under investigation at that point.
The pattern is the same each time. Attackers take contact data plus real transaction or membership details, then use those details to make phishing messages look genuine. A message that quotes your real Yakiniku King membership number will look credible to most recipients. Defenders should expect impersonation campaigns using the Monogatari data, even though none has been reported yet.
The Attack Technique
Unknown. Monogatari has not disclosed how the attacker got in, and its investigation with the system developers is ongoing. The available facts are:
- The target was the member management back end of a consumer mobile app, not the point-of-sale systems or corporate IT.
- The attacker was able to extract almost every record, which points to bulk database access rather than one account at a time.
- Other brand apps were not affected, which suggests the compromise was limited to the Yakiniku King app's system.
The source set includes SentinelOne's entry for CVE-2026-94041. It describes an authenticated SQL injection in admin/add_menu.php of the open-source AdithyaYelloju Restaurant-Management-System, published to NVD on September 20, with a public exploit and no fix available. None of the sources connect this CVE to Monogatari, and nothing suggests that Monogatari uses that project. It is included here only as a reminder that injection flaws in restaurant software admin panels are being found and exploited. It should not be read as the cause of this breach.
What Organizations Should Do
- Audit app and loyalty back ends as crown-jewel systems. Member management databases holding millions of records need the same access control, query logging and alerts on bulk exports as financial systems. Alert on unusually large result sets or sustained enumeration.
- Harden admin interfaces against injection. Use parameterized queries everywhere, put admin panels behind VPN or zero-trust access, and require MFA for every admin account. IMADEYA's response included cutting admin privileges, rotating all admin passwords and enforcing two-factor authentication.
- Review third-party and SaaS integrations. The TEMAIRAZU and IMADEYA cases show that a site controller or linked commerce service can be the point where data leaks. List every system that can read customer data, and tighten each one's permissions.
- Warn customers before the phishing starts. Tell members which channels and domains you actually use (IMADEYA published its official domain), say plainly that you will never ask for card details by message, and explain that a message quoting real account details is not proof it is genuine.
- Watch for brand impersonation. Look for lookalike domains, fake app listings and SMS sender IDs that impersonate your brand. Monitor leak sites and forums for your dataset, and have takedown processes ready.
- Notify regulators and police early. Monogatari, Temairazu and IMADEYA all reported to Japan's Personal Information Protection Commission and/or police, which is the baseline expected under Japan's privacy law.
Sources: Data of over 10M customers exposed in cyberattacks on Japanese firms | CVE-2026-94041: Restaurant Management System SQL Injection | Unauthorized Access Hits Yakiniku King App in Japan, 10.79 Million... | 【Important Notice】Regarding Potential Leakage of Customer Informati... | お客様情報の外部流出の可能性に関するお詫びとお知らせ(第1報) 株式会社いまでやのプレスリリース | Monogatari Corp Probes Major Data Leak at Yakiniku King App | Important News Regarding the Leak of Customer Information Hotel Gr... | 手間いらず「TEMAIRAZU」に不正アクセス 宿泊者情報が閲覧・取得された可能性、WhatsAppなどで不審メッセージセキュリティニ...