Skip to content
>_ITDITDWeb Security Platform

Security Guides

Yakiniku King app breach (about 10.79 million records): names, phone numbers and emails leaked — what members should do

A breach of the Yakiniku King app leaked member numbers, names, emails and phone numbers for 10,788,963 members. What leaked, what did not, and what to do today.

Published 2026-10-05 Updated 2026-10-05 Last verified 2026-10-05 9 min read

For: people registered with the official Yakiniku King app in Japan, and anyone who runs a membership app. This article is based on the official notice from Monogatari Corporation and does not cover attack techniques.

What members should do today

1

Do not follow links or instructions in emails, texts or calls claiming to be Yakiniku King

The leaked data combines name, phone number, email address and member number. With all of that, a scammer can send a message with your correct name and member number.

If you get a message about "apology coupons", "bonus points", "you won a campaign" or "refund procedures", do not open the link; open the app yourself to check. Fake text messages (smishing) are handled the same way (see What is phishing?).

2

Never enter card details or passwords on a page reached from a link

The company says it will not ask for passwords or credit card details. It also says it does not hold payment data in the first place.

A caller who knows your name and member number is not proven genuine by that. Those are exactly the details that leaked. If someone asks for a card number in the name of a refund or apology, treat it as fake.

3

If you reuse the same password elsewhere, separate them

The company says login passwords were not leaked. According to the notice, there is no need to change the app's password right away.

If you use the same password on other services, though, separate them now. A password manager is the realistic way to do the inventory.

4

Stay alert to unknown calls and texts for a while

You can create a new email address, but a phone number is tied to daily life and is not easy to change. The leaked numbers may receive scam calls and texts for a long time, including ones that have nothing to do with Yakiniku King.

Turning on your phone's spam call and spam text filters reduces how many get through (background: Smartphone security basics).

5

Contact the company only at its published number

For questions, call the company's app call center (0120-795-775, 10:00–18:00 Japan time, including weekends and holidays). Use the number on Monogatari Corporation's official website, not one given in a message you received.

What happened (from Monogatari Corporation's notice)

Monogatari Corporation published its apology and notice on October 5, 2026. Everything below is as stated in the company's notice.

  1. Oct 2, 2026 (Fri)

    In the member-management system of the official Yakiniku King app, unauthorized access by a third party was confirmed. The company cut off communications and put defensive measures in place.
  2. Oct 3 (Sat)

    The leak of member data was confirmed.
  3. Oct 5

    Apology and notice published. The company said it is reporting to the Personal Information Protection Commission and filing a damage report with the police, among other steps.
10,788,963
Records leaked (of 10,808,784 app registrations)
Not leaked
Login password, date of birth, gender, postal code, store-visit history
Not held
Payment data such as credit cards
None found
Publication or misuse of the leaked data (as of Oct 5)
What leaked (from Monogatari Corporation's notice)
Who
10,788,963 of the 10,808,784 registrations in the official Yakiniku King app
Items leaked
Member number, name (the name registered in the app), email address, phone number
Not leaked
Login password, date of birth, gender, postal code, store-visit history including points. The company does not hold payment data such as credit cards
Publication or misuse
No publication to the general public or misuse found so far
Cause
Not disclosed. Under detailed investigation with the cooperation of the development company and related companies
Service
The official app continues to operate, with defensive measures against outside unauthorized access in place
Other brands
The same measures were applied to the official apps of the company's other brands, and the company says no leak has occurred there
Contact
App call center, 0120-795-775 (10:00–18:00 Japan time, including weekends and holidays)

What the leaked items can be used for in combination

None of these items is rare on its own, but together they make scam messages look genuine. Dates of birth and addresses were not included this time; what stands out is that three ways to reach you (name with phone and email) leaked together.

Name + email + member number

↓

Fake coupon or refund emails with your correct name and member number

→ Do not open links; check in the official app

Name + phone number

↓

Fake texts and calls that use your name

→ Never give card details; use spam text filters

Combinations of the leaked items and the matching step for members

Not leaked, according to the company

  • Login password
  • Date of birth, gender and postal code
  • Store-visit history, including points
  • Payment data (never held)

Leaked

  • Member number
  • Name (the name registered in the app)
  • Email address (changeable, but a hassle)
  • Phone number (not easy to change)

How to read it: 'no misuse found' does not mean 'safe from now on'

The company says no publication or misuse of the leaked data has been found so far. That means nothing has been found yet, not that the data will never be used.

Phone numbers often stay the same for years, so they can be used in scam messages months or years later. Stay alert to messages that use this incident as a reason to contact you.

The leaked name is described as the "app registration name". If you registered under a nickname and receive a message addressed to that nickname, it may be using data from this leak.

For those who run membership apps

The leaked records cover more than 99% of app registrations: the contact details of almost every member leaked from a single member-management system. The cause has not been disclosed, so this section sticks to points that any service with a similar setup can review. Limiting what an app's server can read is covered in the Seicomart app breach; here we add points specific to the scale of this incident.

1

Cap how many records one operation or one account can read

Even admin screens and management functions rarely need to read millions of records at once in normal work. Set a cap on the records returned by one search or export, and move full exports into a separate procedure (approval, or limited hours).

Setting limits and alerting when they are reached is covered in Rate limiting and abuse control.

2

Record rows read per hour and alert on the difference from normal

As a first step, record how many rows are read from the member database each hour and notify someone when the count passes several times the usual level. Many cloud databases and audit-log features let you set alerts on row counts or run time.

Looking at reads at unusual hours or from unusual sources, not just the count, also makes anomalies easier to spot.

3

List every path that can read all members' data, and narrow it down

Besides the path used by the app, a member-management system often has connections for admin screens, development and maintenance. List which paths can read all members' data, shut off unused connections, and require multi-factor authentication and source restrictions on the rest (background: Authentication vs. authorization).

Sources (public record)

The facts in this article come from the public sources below. Undisclosed methods or causes of the intrusion are not speculated on.

  • Monogatari Corporation, apology regarding the leak of personal data from unauthorized third-party access to the member-management system of the official Yakiniku King app (October 5, 2026, Japanese) — monogatari.co.jp
  • ITmedia NEWS (October 5, 2026, Japanese) — itmedia.co.jp
  • Nikkei, report on the Yakiniku King customer data leak of more than 10 million records (October 5, 2026, Japanese) — nikkei.com
  • ASCII, report that data on 10.78 million people leaked, covering almost all app registrants (October 5, 2026, via Yahoo! News Japan, Japanese) — news.yahoo.co.jp

Update history

2026-10-05: First version, based on Monogatari Corporation's notice of October 5. The company says it is investigating the cause and how the access happened; this article will be updated when that is published.

FAQ

QWhat was leaked in the Yakiniku King app breach?
A

According to Monogatari Corporation's notice of October 5, 2026, 10,788,963 of the 10,808,784 registrations in the official Yakiniku King app were leaked. The items are member number, name (the name registered in the app), email address and phone number.

QWhat was not leaked?
A

The company says the login password, date of birth, gender, postal code and store-visit history including points held in the app were not leaked. It says it does not hold payment data such as credit card details in the first place.

QAm I affected?
A

10,788,963 of 10,808,784 registrations were leaked, so almost everyone registered is affected. If you are registered with the official Yakiniku King app, it is realistic to act as if you are affected. The company says no leak has occurred in the official apps of its other restaurant brands.

QShould I change my password?
A

The company says login passwords were not leaked. If you use the same password as the Yakiniku King app on other services, though, this is a good moment to stop reusing it.

QWhat scams should I watch for?
A

Because names, phone numbers, email addresses and member numbers were leaked together, emails, texts and calls posing as Yakiniku King with coupons, points, campaigns, apologies or refunds are possible. The company says it will not ask for passwords or credit card details. Do not open links in such messages; check in the official app you open yourself. The company's app call center is 0120-795-775 (10:00–18:00 Japan time, including weekends and holidays).

QWhat caused the breach?
A

As of October 5, 2026, the cause and how the unauthorized access became possible had not been disclosed. The company says it is investigating in detail with the cooperation of its development company and related companies. It also says it is reporting to Japan's Personal Information Protection Commission and filing a damage report with the police.