Monogatari Corporation confirmed that Yakiniku King’s official app member-management system suffered unauthorized access detected on October 2, 2026, with data leakage verified on October 3, affecting 10,788,963 of 10,808,784 registered users. Exposed fields: member number, name as registered in the app, email, and phone. Login passwords, birthdates, gender, postal codes, point-linked store history, and payment cards were not in the leaked set per the company. Notice: 261005_news. Canonical: https://breachhistory.com/monogatari/monogatari-yakiniku-king2026 (/monogatari/monogatari-yakiniku-king2026).
This is a verified Yakiniku King data breach at nearly all registered accounts — rare scale for a single restaurant-brand app — with company attestation rather than forum marketing. What this is not: a payment-card database compromise; Monogatari says it does not retain card data on that system.
What happened over October 2–3
On Friday, October 2, Monogatari detected unauthorized access to the Yakiniku King app’s member-management backend. Engineers cut communication and applied defensive measures, but follow-up review showed member records had indeed left the protected environment. On Saturday, October 3, the company confirmed leakage and began regulatory and customer-notification steps.
The app itself kept running — Monogatari restored external access with additional defenses rather than leaving diners unable to book or scan points. Sister brands’ apps received the same hardening; Monogatari reports no parallel leaks there.
Scale — 10.79 million of 10.81 million registrations
Out of 10,808,784 total app registrations, 10,788,963 records leaked — roughly 99.8% of the user base. That is effectively whole-population exposure for anyone who ever kept a Yakiniku King app account active or dormant.
Public reporting has not yet explained the small gap between total registrations and leaked rows — inactive test accounts, incomplete registrations, or forensic exclusions are plausible, but Monogatari has not indexed English detail on the delta at draft time.
Timeline
- October 2, 2026 — Intrusion detected; network isolation and defensive measures applied.
- October 3, 2026 — Leak confirmed; public apology posted; other brand apps hardened.
- October 3 onward — Personal Information Protection Commission reporting and police victim reports per notice.
- Ongoing — Cause investigation with developers and affiliates; call center stands up for member questions.
What remains unknown publicly
- Attack vector — API abuse, stolen admin credentials, supplier compromise, or web vulnerability — not disclosed in the initial news post.
- Whether files were published on leak sites — company mentions no evidence of public paste or misuse yet, not denial of exfiltration.
- Dwell time before October 2 — detection date only, not first access.
What data was exposed
- Member number — loyalty identifier used in app and stores.
- Name (as entered for app registration)
- Email address
- Phone number
Even without passwords, pairing member numbers with phones enables SMS phishing that quotes accurate account labels — “Yakiniku King member 08xxxxx verification required.”
What Monogatari says was not exposed
- Login passwords
- Date of birth, gender, postal code
- Store visit history including point balances
- Payment card data — not stored on this system
Scammers who claim “your last visit to store #123 earned points — click here” are likely bluffing unless they source data elsewhere — purchase history was not in the attested leak.
Who is at risk
Nearly every Yakiniku King app user — plan on being in the 10.79 million set unless Monogatari later publishes exclusions.
Families sharing one phone number for reservations — vishing may name the primary registrant.
Corporate employees enrolled for team lunches — work email in the app field becomes a BEC pivot if reused.
Phishing to expect after the Yakiniku King breach 2026
- Fake coupon or birthday offer SMS with malicious links.
- Account cancellation warnings demanding passwords Monogatari says it will never ask for by email.
- Third-party delivery impersonation — less credible if scammers cite order history you know was not leaked.
Restaurant-chain context
Monogatari operates multiple grill and dining brands; only Yakiniku King’s member DB appears in this notice. The October 2026 wave of Japanese hospitality app intrusions puts pressure on shared developers and cloud hosts — without evidence Monogatari’s vendors were the entry point, security teams should still audit API keys shared across brands.
What the company and regulators said
Monogatari apologized, listed fields, denied password and payment exposure, and opened a dedicated app call center at 0120-795-775 (10:00–18:00 daily including weekends/holidays). It reported to the Personal Information Protection Commission and filed police reports.
No public misuse yet does not mean data stayed private — only that Monogatari has not seen fraud attributed to the leak at notice time.
What you should do
- Expect SMS and email scams using Yakiniku King branding; verify through official app or monogatari.co.jp.
- Do not share passwords or card numbers in response to cold contacts — Monogatari repeats it will not ask.
- Rotate passwords if you reused your app login elsewhere — even though login passwords were not in the leaked columns, email accounts remain exposed.
- Enable MFA on email tied to the app registration.
- Use the call center for incident-specific questions instead of store managers.
- Bookmark /monogatari/monogatari-yakiniku-king2026 for scope updates.
Was I affected?
If you registered for the Yakiniku King app, assume yes — the leaked count covers essentially the entire registration base. Official direct mail or in-app messages may follow; absence of contact does not safely exclude you given the 99.8% ratio.
App continuity vs data harm
Monogatari chose to keep the app online with stronger monitoring — good for diners booking tables, but it means users must distinguish legitimate push notifications from phishing. Check sender domains and in-app message centers before tapping links.
Developer and affiliate investigation
The notice cites cooperation with development companies and related firms to trace cause. Watch for future updates naming patches or supplier responsibilities — initial posts rarely include CVEs.
Comparison with smaller member leaks
Ten-million-row contact leaks are bulk spam fuel. Without passwords or visit history, criminals focus on getting you to type credentials into fake login pages. Knowing your member number makes their templates sharper — treat any authentication prompt as suspicious unless you opened the app yourself.
Long-term monitoring
When breach populations approach entire user bases, HIBP-style loads and forum samples may appear later even if day-one misuse reports stay quiet. Monitor identity services if you used real names and mobile numbers tied to banking SMS recovery.
Yakiniku King within Monogatari’s brand portfolio
Monogatari Corporation runs multiple grilled-meat and dining concepts; Yakiniku King is among its highest-volume app-enabled brands. This incident isolates Yakiniku King’s member-management database — not necessarily every reservation system company-wide.
Nearly total registration overlap
Leaking 10,788,963 of 10,808,784 accounts means only about twenty thousand registrations sit outside the confirmed leak set. Unless Monogatari later explains that delta, operational advice should assume universal exposure for active and dormant app users alike.
Passwords excluded — login flow still targeted
Monogatari states login passwords did not leak. Attackers will still send fake login pages because users do not read field-level notices. Always open the app from your home screen icon or typed official URL — never from SMS links.
Store visit history and points stay private — per notice
Scammers cannot truthfully cite your last visit date or point balance from this leak alone. Use that knowledge to debunk phishing: if a message quotes visit details, it likely comes from another source or is fabricated.
October 2–3 weekend response
Detecting on Friday and confirming Saturday fits a pattern where attackers hit before weekend staffing peaks. Monogatari’s decision to keep service running suggests confidence in containment plus customer demand for weekend dining reservations.
Sister brands hardened
Applying defenses across other Monogatari apps reduces cross-brand pivot risk if attackers shared hosting or API keys. No leaks reported elsewhere yet — good sign, but not a guarantee other databases were unreachable.
Call center load expectations
0120-795-775 will spike after national news coverage. Prepare account details before calling; avoid sharing passwords or card numbers to “verify” identity to agents — real agents follow the same policy as the web notice.
Police reports and PPC filing
Monogatari references police victim reports and PPC notification — standard for large Japanese PII events. Law enforcement may not contact each victim individually; the filings support aggregate investigation.
Grill-chain seasonality and tourism
Autumn travel increases app usage for queue skipping at popular locations. Tourists with temporary Japanese numbers may still appear in the leak if they installed the app during trips — watch roaming SMS carefully.
Member number on receipts and apps
Member numbers appear in app UI and sometimes marketing PDFs. Public knowledge of formatting helps scammers sound legitimate. Monogatari will not ask you to recite member numbers to random callers for “verification.”
Email vs phone as primary channel
Both channels were exposed. If you preferred phone for login OTPs, consider switching email factors where supported after you rotate passwords on other services.
Developer cooperation mentioned
The notice credits development companies and affiliates with investigation support — hinting third-party engineering involvement typical for multi-brand restaurant apps. Future updates may clarify whether a supplier patch drove the intrusion.
No public dump yet
Monogatari says no evidence data was published broadly or misused at notice time. Criminals may still hold private copies. Continue monitoring for HIBP loads or forum samples in coming weeks.
Bulk contact spam economics
Ten million Japanese mobile numbers attract domestic spam operators and offshore call centers. Expect waves of “points expiring” SMS unrelated to actual point data — user education is the main defense when visit history stayed internal.
Corporate employees using personal emails
Work-from-personal-email registrations leak professional addresses into a consumer breach — increasing BEC risk if passwords were reused on Microsoft 365 or Google Workspace.
ASCII national news amplification
Japanese tech press summarized Monogatari’s leak alongside other October app incidents, driving call-center volume. Expect delayed callbacks; use official web updates when phone lines busy.
App registration name vs legal name
The notice specifies names as entered in the app — nicknames or partial names may appear. Scammers guessing “Yakiniku King” branding still sound credible with member numbers.
Group dining and shared phones
Tables often register one member for group points. One leaked row may represent several diners’ shared contact info — explain phishing risks to friends whose numbers you entered.
Future HIBP or monitoring loads
When breach corpora appear in monitoring services, enroll the email you used for Yakiniku King registration. Monogatari has not announced credit monitoring at indexing time.
Physical dining safety
Kitchen and payment operations continue; this is a digital member-database event. Tip and pay as usual while ignoring digital “account lock” threats.
Reservation peaks and account recovery
Weekend queues at popular Yakiniku King locations already stress app performance; post-breach phishing adds social congestion. If you reset app credentials after official guidance, do so only inside the legitimate app store listing — not via QR codes on restaurant table tents unless Monogatari explicitly publishes them.
National scale in perspective
More than ten million contact records rival national telecom marketing leaks in raw count, even though field sensitivity is lower than passport or payment breaches. Criminals optimize for volume: expect broad untargeted SMS waves alongside sharper messages that include your member number if samples circulate underground.
Loyalty competition among grill chains
Yakiniku King competes with other all-you-can-eat brands whose apps also hold member numbers. A scam message might name the wrong chain while using your real phone number from this leak — skepticism applies industry-wide.
Press and IR contacts for journalists
Monogatari listed [email protected] for media inquiries separate from the member hotline. Readers seeking technical IoCs should watch official releases rather than influencer threads that remix ASCII headlines with unverified dump sizes.
For the Yakiniku King breach 2026, Monogatari’s confirmed October 2 detection and October 3 leakage acknowledgment — 10,788,963 member numbers with names, emails, and phones — is the baseline for “was I affected?” unless you are among the tiny fraction of registrations outside the leaked set.
Because login passwords and point-linked visit history were not in the attested leak, prioritize scam awareness over password-reset panic — but still harden email and phone accounts that attackers can target using the contact fields Monogatari confirmed.
Keep the official app updated, use the 0120-795-775 hotline for incident questions, and ignore cold callers who claim they need your payment card to “re-lock” a compromised member profile.
Monogatari’s October 2026 notice is the authoritative source for what the Yakiniku King data breach included and excluded; treat any third-party “full database download” advertisement as untrusted malware or recycled data until it matches the company’s field list and timing.
If you deleted the app years ago but registered before the leak window closed, assume your row remains in the 10,788,963 set until Monogatari publishes exclusions — retention policies for dormant accounts were not detailed in the first news post.
Franchise staff at individual Yakiniku King locations are not the right channel for forensic detail; corporate communications and the 0120-795-775 hotline carry the official field list and any future count revisions.
Canonical record and sources
BreachHistory indexes Monogatari/Yakiniku King as company-confirmed with 10,788,963 records (member number, name, email, phone). Update at https://breachhistory.com/monogatari/monogatari-yakiniku-king2026.
Yakiniku King app users should internalize that essentially the entire membership file with contact details is out, passwords and point histories are not according to Monogatari, and the safe response is skeptical treatment of any message quoting your member number unless you initiated contact through official channels.