Security Guides
Yakiniku King app breach (about 10.79 million records): names, phone numbers and emails leaked — what members should do
A breach of the Yakiniku King app leaked member numbers, names, emails and phone numbers for 10,788,963 members. What leaked, what did not, and what to do today.
For: people registered with the official Yakiniku King app in Japan, and anyone who runs a membership app. This article is based on the official notice from Monogatari Corporation and does not cover attack techniques.
What members should do today
Do not follow links or instructions in emails, texts or calls claiming to be Yakiniku King
The leaked data combines name, phone number, email address and member number. With all of that, a scammer can send a message with your correct name and member number.
If you get a message about "apology coupons", "bonus points", "you won a campaign" or "refund procedures", do not open the link; open the app yourself to check. Fake text messages (smishing) are handled the same way (see What is phishing?).
Never enter card details or passwords on a page reached from a link
The company says it will not ask for passwords or credit card details. It also says it does not hold payment data in the first place.
A caller who knows your name and member number is not proven genuine by that. Those are exactly the details that leaked. If someone asks for a card number in the name of a refund or apology, treat it as fake.
If you reuse the same password elsewhere, separate them
The company says login passwords were not leaked. According to the notice, there is no need to change the app's password right away.
If you use the same password on other services, though, separate them now. A password manager is the realistic way to do the inventory.
Stay alert to unknown calls and texts for a while
You can create a new email address, but a phone number is tied to daily life and is not easy to change. The leaked numbers may receive scam calls and texts for a long time, including ones that have nothing to do with Yakiniku King.
Turning on your phone's spam call and spam text filters reduces how many get through (background: Smartphone security basics).
Contact the company only at its published number
For questions, call the company's app call center (0120-795-775, 10:00–18:00 Japan time, including weekends and holidays). Use the number on Monogatari Corporation's official website, not one given in a message you received.
What happened (from Monogatari Corporation's notice)
Monogatari Corporation published its apology and notice on October 5, 2026. Everything below is as stated in the company's notice.
Oct 2, 2026 (Fri)
In the member-management system of the official Yakiniku King app, unauthorized access by a third party was confirmed. The company cut off communications and put defensive measures in place.Oct 3 (Sat)
The leak of member data was confirmed.Oct 5
Apology and notice published. The company said it is reporting to the Personal Information Protection Commission and filing a damage report with the police, among other steps.
- Who
- 10,788,963 of the 10,808,784 registrations in the official Yakiniku King app
- Items leaked
- Member number, name (the name registered in the app), email address, phone number
- Not leaked
- Login password, date of birth, gender, postal code, store-visit history including points. The company does not hold payment data such as credit cards
- Publication or misuse
- No publication to the general public or misuse found so far
- Cause
- Not disclosed. Under detailed investigation with the cooperation of the development company and related companies
- Service
- The official app continues to operate, with defensive measures against outside unauthorized access in place
- Other brands
- The same measures were applied to the official apps of the company's other brands, and the company says no leak has occurred there
- Contact
- App call center, 0120-795-775 (10:00–18:00 Japan time, including weekends and holidays)
What the leaked items can be used for in combination
None of these items is rare on its own, but together they make scam messages look genuine. Dates of birth and addresses were not included this time; what stands out is that three ways to reach you (name with phone and email) leaked together.
Name + email + member number
↓→
Fake coupon or refund emails with your correct name and member number
→ Do not open links; check in the official app
Name + phone number
↓→
Fake texts and calls that use your name
→ Never give card details; use spam text filters
Not leaked, according to the company
- Login password
- Date of birth, gender and postal code
- Store-visit history, including points
- Payment data (never held)
Leaked
- Member number
- Name (the name registered in the app)
- Email address (changeable, but a hassle)
- Phone number (not easy to change)
How to read it: 'no misuse found' does not mean 'safe from now on'
The company says no publication or misuse of the leaked data has been found so far. That means nothing has been found yet, not that the data will never be used.
Phone numbers often stay the same for years, so they can be used in scam messages months or years later. Stay alert to messages that use this incident as a reason to contact you.
The leaked name is described as the "app registration name". If you registered under a nickname and receive a message addressed to that nickname, it may be using data from this leak.
For those who run membership apps
The leaked records cover more than 99% of app registrations: the contact details of almost every member leaked from a single member-management system. The cause has not been disclosed, so this section sticks to points that any service with a similar setup can review. Limiting what an app's server can read is covered in the Seicomart app breach; here we add points specific to the scale of this incident.
Cap how many records one operation or one account can read
Even admin screens and management functions rarely need to read millions of records at once in normal work. Set a cap on the records returned by one search or export, and move full exports into a separate procedure (approval, or limited hours).
Setting limits and alerting when they are reached is covered in Rate limiting and abuse control.
Record rows read per hour and alert on the difference from normal
As a first step, record how many rows are read from the member database each hour and notify someone when the count passes several times the usual level. Many cloud databases and audit-log features let you set alerts on row counts or run time.
Looking at reads at unusual hours or from unusual sources, not just the count, also makes anomalies easier to spot.
List every path that can read all members' data, and narrow it down
Besides the path used by the app, a member-management system often has connections for admin screens, development and maintenance. List which paths can read all members' data, shut off unused connections, and require multi-factor authentication and source restrictions on the rest (background: Authentication vs. authorization).
Sources (public record)
The facts in this article come from the public sources below. Undisclosed methods or causes of the intrusion are not speculated on.
- Monogatari Corporation, apology regarding the leak of personal data from unauthorized third-party access to the member-management system of the official Yakiniku King app (October 5, 2026, Japanese) — monogatari.co.jp
- ITmedia NEWS (October 5, 2026, Japanese) — itmedia.co.jp
- Nikkei, report on the Yakiniku King customer data leak of more than 10 million records (October 5, 2026, Japanese) — nikkei.com
- ASCII, report that data on 10.78 million people leaked, covering almost all app registrants (October 5, 2026, via Yahoo! News Japan, Japanese) — news.yahoo.co.jp
Update history
2026-10-05: First version, based on Monogatari Corporation's notice of October 5. The company says it is investigating the cause and how the access happened; this article will be updated when that is published.
Read next
- Follow-on scams: What is phishing? / Smartphone security basics
- Passwords: Choosing a password manager
- Other Japanese incidents at the same time: The Seicomart app breach / The Abahouse breach
- Other 2026 incidents: list of breaches and cyberattacks (Japan and worldwide)
FAQ
QWhat was leaked in the Yakiniku King app breach?
According to Monogatari Corporation's notice of October 5, 2026, 10,788,963 of the 10,808,784 registrations in the official Yakiniku King app were leaked. The items are member number, name (the name registered in the app), email address and phone number.
QWhat was not leaked?
The company says the login password, date of birth, gender, postal code and store-visit history including points held in the app were not leaked. It says it does not hold payment data such as credit card details in the first place.
QAm I affected?
10,788,963 of 10,808,784 registrations were leaked, so almost everyone registered is affected. If you are registered with the official Yakiniku King app, it is realistic to act as if you are affected. The company says no leak has occurred in the official apps of its other restaurant brands.
QShould I change my password?
The company says login passwords were not leaked. If you use the same password as the Yakiniku King app on other services, though, this is a good moment to stop reusing it.
QWhat scams should I watch for?
Because names, phone numbers, email addresses and member numbers were leaked together, emails, texts and calls posing as Yakiniku King with coupons, points, campaigns, apologies or refunds are possible. The company says it will not ask for passwords or credit card details. Do not open links in such messages; check in the official app you open yourself. The company's app call center is 0120-795-775 (10:00–18:00 Japan time, including weekends and holidays).
QWhat caused the breach?
As of October 5, 2026, the cause and how the unauthorized access became possible had not been disclosed. The company says it is investigating in detail with the cooperation of its development company and related companies. It also says it is reporting to Japan's Personal Information Protection Commission and filing a damage report with the police.