Key takeaways

  • Monogatari Corporation (物語コーポレーション), which runs the all-you-can-eat barbecue chain Yakiniku King (焼肉きんぐ), said on October 5, 2026 that attackers broke into the member management system of the chain's official app.
  • Data on 10,788,963 accounts leaked: member numbers, names, email addresses and phone numbers. That is 99.8% of the app's 10.8 million registered users.
  • Passwords, dates of birth, gender, postcodes, visit history and points were not leaked, and the company holds no payment card data.
  • The company has not said how the attackers got in. It warns that the data may be used for phishing emails and texts.

What happened#

Date (2026) Event
Oct 2 (Fri) Unauthorized access to the app's member management system confirmed. Monogatari cuts off communications and takes defensive measures
Oct 3 (Sat) Monogatari confirms that member data has leaked
Oct 5 (Mon) Notice published, and a timely disclosure filed with the Tokyo Stock Exchange

The app is still running, with defensive measures in place. Monogatari says it has taken the same measures for the apps of its other restaurant brands, and that no data leaked from them.

It is strengthening security and monitoring with the app's development company and other related companies, and says it is reporting the incident to the Personal Information Protection Commission and filing a report with the police.

What leaked#

Data Status
Member number Leaked
Name (as registered in the app) Leaked
Email address Leaked
Phone number Leaked
Login password Not leaked
Date of birth, gender, postcode Not leaked
Visit history, including points Not leaked
Payment card data Not held by the company

Who is affected: 10,788,963 of 10,808,784 registered app users. The figures are registrations, not unique people: someone who registered more than once may be counted more than once.

Monogatari says it has found no sign so far that the data has been published or misused.

What we don't know yet#

Monogatari has not said:

  • How the attackers got into the member management system, or when the access began
  • Whether the system is run by the company or by the development company
  • Whether it will notify each affected member directly
  • Whether a ransom has been demanded. As of October 5, we found no listing on ransomware leak site trackers

Our analysis#

Nearly everyone, at once#

The leak covers 99.8% of registered users. This is not a handful of compromised accounts: it is close to the entire member list. At 10.8 million records, it is larger than the Times Car breach of 6.6 million accounts in September.

The data taken is narrow but useful. A name, email address and phone number, linked to a membership of a well-known restaurant chain, are exactly what a scammer needs to send a believable message.

Phishing material, ready to use#

Monogatari warns that the data may be used for impersonation emails and phishing. That risk is not hypothetical. Last week, ABAHOUSE learned of its breach because customers were already receiving scam emails that used their real order data, within about a day of the intrusion.

Yakiniku King's data has no order details, but it has something else: phone numbers. Text message scams are common in Japan, and IPA's white paper reports that the share of illicit bank transfers that started with an SMS roughly tripled in 2025. Email addresses can be changed. Phone numbers usually are not.

Another app member database#

This is the latest in a run of breaches of consumer membership systems in Japan. In the past two weeks, Seicomart's app server was used to reach its member server, Times Car lost data on 6.6 million accounts, and Yamato and ABAHOUSE disclosed leaks of customer and order data. There is no sign the incidents are connected. But they share one feature: a large database of customers sitting behind a system that faces the internet.

A short, factual notice#

Monogatari's notice is clear about what leaked, gives exact numbers, and lists what did not leak. It discloses within three days of finding the intrusion. What it does not yet give is any explanation of how it happened, or a date when the investigation will report.

What this means for readers#

  • If you have the Yakiniku King app, assume your name, email address and phone number are in the hands of scammers.
  • Be suspicious of emails, text messages and calls that mention Yakiniku King, coupons, points or prizes, especially ones with links. Monogatari says it will never ask for passwords or card details.
  • Your password was not leaked, according to the company. If you reused your Yakiniku King password elsewhere, changing it is still a good habit.
  • Questions: Monogatari's dedicated call center for the app is 0120-795-775 (toll-free in Japan, 10:00–18:00).

Japanese terms at a glance#

Japanese Reading Meaning
焼肉きんぐ Yakiniku Kingu Yakiniku King, all-you-can-eat barbecue chain
物語コーポレーション Monogatari Kōporēshon Monogatari Corporation, the operator
会員管理システム kaiin kanri shisutemu Member management system
アプリ登録名 apuri tōroku mei Name registered in the app
適時開示 tekiji kaiji Timely disclosure to the stock exchange
被害届 higai todoke Damage report filed with the police

We will update this article when Monogatari publishes the cause.