DEV Community

Ahsan Luqman
Ahsan Luqman

Posted on Originally published at aliasfleet.com on

10.79 Million Yakiniku King Users Had Emails Leaked in Monogatari Breach

10,788,963. That is how many Yakiniku King app members Monogatari Corporation says lost personal data to an intruder this month, out of 10,808,784 registered users. Nearly the entire membership. The leaked data: names, email addresses, phone numbers, member numbers.

The detail I keep coming back to is what the app is for. Nobody joins a barbecue restaurant's rewards app expecting to land in a breach file; you join to book a table and get a coupon. I run AliasFleet, an email-alias service built so one site's spill stays on that site, and this is the exact scenario it exists for. The signup that felt harmless and turned out not to be.

Monogatari Corporation's October 5 notice disclosing the Yakiniku King app breach: 10,788,963 of 10,808,784 registered member records leaked

What leaked, and what did not

Monogatari's announcement is unusually specific about the split, and the split matters.

Leaked Not leaked
Member number Login password
Name (app registration name) Date of birth
Email address Gender
Phone number Postal code
Store usage history and points
Payment card data (never held by the company)

No passwords means no credential-stuffing wave from this file, and no card data means nobody is draining accounts with it. But names, emails and phone numbers are the complete kit for a phishing campaign, and unlike a password, you cannot change your name and phone number with a settings page. This file stays useful to scammers for years.

The timeline so far

Monogatari says it spotted the unauthorized access on October 2, blocked it, and confirmed the leak on October 3. It went public on October 5 with its own notice (in Japanese), the same week Daiwa Securities disclosed that a vendor's servers may have exposed data on up to 110,000 brokerage clients. The two incidents are unrelated, but the timing tells you something about the season Japanese companies are having.

The company has reported the incident to Japan's Personal Information Protection Commission and is filing a police report. The cause, the route in and the attacker's identity are still under investigation, which means this story is not finished. Other Monogatari brands, like Marugen Ramen, are not affected, and the Yakiniku King app is still running with countermeasures in place.

The peripheral system pattern

There is a pattern forming, and Monogatari fits it. The attackers are not going for the vault. In the last week, Korean banks bled through loan-agent and sales-support systems: Shinhan through a loan-agent service (about 25,000 customers), Hana through its ODS operations support system (89 customers), KB Kookmin through an employee mobile support system (119 customers). In Japan, Daiwa's breach came through a vendor's inquiry-management server. Monogatari's member management system is the same kind of target: not the core business, just the system that happens to hold everyone's contact details. The vault gets the security budget. The reservation app gets the customers.

Why this one deserves your attention

When a breach takes 99.8 percent of registered users, your odds of being in the file are not a lottery. They are a certainty. And as of the company's announcement, nobody has confirmed any misuse of the data. That sounds reassuring. It is not, quite. It means the file exists and its future is unknown. The first confirmed misuse usually arrives as phishing, and Monogatari is already warning about it: spoof emails and fake messages posing as the company, suspicious texts and calls, links and attachments you should not open.

The company says it will never ask you for passwords or card details by email or phone. That line is worth remembering, because the scammers will ask.

If you used the Yakiniku King app, do this

  1. Expect the phishing. Any email or text about this breach that asks you to click a link is suspect. Open the app or go to the company's site yourself instead.
  2. The company will never ask for your password or card details. Anyone who does is not the company.
  3. Turn on multifactor authentication on your email account. Your email is the recovery address for everything else you own, and it is in this file.
  4. Check Have I Been Pwned once the breach is added. It is the canonical place to see which of your addresses have leaked and where.
  5. Do not panic about payments. The company holds no card data, and login passwords were not leaked, so this one is about impersonation, not account takeover.

The full ordered version of the standard response lives in our breach-response guide.

The fix that works next time

You cannot un-leak this file. Nobody can. The copies that exist will keep circulating, and 10.79 million people will spend the next few years deleting phishing mail they can trace back to a barbecue app.

What you can do is stop the next one from working the same way. Give every site its own email alias. When the next restaurant app, shop or forum gets opened up, the address in the file belongs to that site only. You pause it, the phishing dies, and your real address never appears in the dump because you never handed it out. And when the phishing starts arriving on that address, the address itself names the source, which is the leak-tracing mechanism working exactly as designed. That is the whole mechanism: one alias per site. The leak dies with that address instead of following you around the internet.

If you have never used one: this is what an email alias is. The set-up guide takes about two minutes.

What I could not verify

One admission. The company's notice is in Japanese, and I do not read Japanese, so the facts above come from Japanese press reporting (Jiji, Sankei, ITmedia, INTERNET Watch, Reuters Japan) and translated text, cross-checked against the company's own notice page. If any detail here differs from the Japanese original, the original wins. Second, the investigation is still open: the cause, the route in and the full timeline of the intrusion are unknown, and the company has not said whether it will notify every affected member individually. I will update this piece when Monogatari publishes more.

Your barbecue app should not be the reason your inbox gets worse. Next time, hand it an address that belongs to it alone.

Top comments (0)