BREACH

Japan’s breach wave widens: Yakiniku King 10.8M, Mr Max 1.7M, and one FAQ vendor that exposed Daiwa and Citizen

Another batch of Japanese companies disclosed intrusions on Oct 5 and 6. Monogatari says data on 10,788,963 of its 10,808,784 Yakiniku King app members leaked. Discount retailer Mr Max says up to 1,735,154 app and online-store members were hit. GMO Research & AI says up to 948,498 infoQ survey members, every member record it holds, were taken. And FAQ-software vendor Scala Communications says an intruder in its i-ask admin site pulled inquiry data for up to five client companies; Daiwa Securities and Citizen Watch have since disclosed. Chief Cabinet Secretary Minoru Kihara said on Oct 6 the government takes it “very seriously.” Attacker: Undisclosed. No link between the incidents has been confirmed.

Oct 6, 2026 · 3 min read

This sits on top of Park24’s Times Car breach from late September (our brief), and Kyodo reports Yamato Transport and Sagawa Express have also said customer names and addresses may have leaked. The new piece worth an enterprise buyer’s attention is the vendor hit. Daiwa and Citizen say their own systems weren’t touched. Their data went out through a contact-form vendor anyway.

The vendor hit. Scala, the parent of Scala Communications, says a third party logged into the i-ask admin site illegitimately between about 8:30 PM on Oct 2 and 8:00 AM on Oct 3 (JST), planted a malicious program on a Scala-managed server, and may have pulled inquiry records from the databases of client environments running on that same server. That’s up to five clients and up to 713,126 inquiry records; the count includes repeat inquiries from the same person, and Scala is still deduplicating it. A database monitoring alert tipped them off on the morning of Oct 3. Scala won’t name clients. Daiwa says about 110,000 customers’ names, email addresses and account numbers may be out, roughly 220,000 records in total, and that the data can’t be used to log in or trade. Citizen says about 100,000 people who used the contact forms for Citizen, Bulova and Frederique Constant are affected: names, addresses, phone numbers and emails, plus any bank account or card details people typed into the message box.

The direct hits. Monogatari says it found the intrusion into the Yakiniku King member system on Oct 2 and confirmed the leak on Oct 3: membership numbers, names, emails and phone numbers; no passwords or payment data. Cause is under investigation. Mr Max says it spotted suspicious access on the evening of Oct 3 and that the intruder abused a function of the software behind its app and online store; member IDs, names, emails and phones went out, and addresses, birth dates, cards and passwords did not. GMO Research & AI says attackers got in from Oct 2 by exploiting a vulnerability in software its site used, and took names, addresses, birth dates, phone numbers, emails and encrypted passwords. They also swapped 611 members’ points, ¥2,869,500 worth, for Amazon gift codes. GMO will cover that in full. The vulnerable product and CVE: Undisclosed.

What we’d do this morning. List every SaaS that collects free text from your customers: contact forms, FAQ and help desks, chat widgets, survey tools. They hold whatever people typed, and Citizen just told its customers that includes bank and card numbers. Ask each vendor three things. Does our tenant share a server or database with other customers? Is admin login behind MFA and IP allowlisting? Can uploaded files execute? One of Scala’s fixes was blocking uploaded files from running as programs, which tells you where to look on your own web tier: new executable files in upload paths and admin sessions from unfamiliar IPs. Note the timing, too. Monogatari, GMO, Mr Max and Scala all describe intrusions starting Friday night, Oct 2, or Saturday, Oct 3, so weekend on-call coverage matters as much as the control list.

The market read. Daiwa shares gave up gains and fell almost 1% on Oct 5 after its notice, per Bloomberg via The Japan Times. Daiwa says it’s now reviewing all of its existing outsourcing vendors. Expect Japanese boards to ask for the same, which helps third-party risk, SaaS security posture and attack surface vendors selling into Japan.

Desk sheet: Monogatari 10,788,963 of 10,808,784 (Oct 5 notice). Mr Max up to 1,735,154 (Oct 6). GMO Research & AI infoQ up to 948,498; 611 point swaps, ¥2,869,500 (Oct 5). Scala Communications i-ask up to 713,126 inquiry records across up to five clients, intrusion Oct 2, 20:30 to Oct 3, 08:00 JST (Oct 6). Daiwa about 110,000 people, about 220,000 records (Oct 5). Citizen about 100,000 people (Oct 6). Attacker, initial access for Monogatari, and the vulnerable product at GMO: Undisclosed.

Sources