← Incident database

applynow-bi-2026 · Disclosed 2026-09-09

ApplyNow(吉野家・橿原市・富士市): unauthorized access and impact

A vulnerability in outsourced ApplyNow analytics was exploited; applicant data remained after contract termination. Scope includes 4,998 Yoshinoya applications, 368 Hanamaru applications, and 418 recruiter accounts; records are not distinct-person counts. The previously contracted ApplyNow platform was accessed without authorization. 313 Kashihara application records may be affected; the count remains provisional. Separately stored images and videos were excluded. The ApplyNow intrusion leaked Fuji City applicants’ information. The follow-up confirmed 815 leaked records, updating the provisional estimate of about 800; videos were excluded.

Supply chain / CICause unresolved / undisclosed

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    A vulnerability in outsourced ApplyNow analytics was exploited; applicant data remained after contract termination.

    [s2][s1]p.1 §1-2 / p.2 §4
  • Reported fact

    Scope includes 4,998 Yoshinoya applications, 368 Hanamaru applications, and 418 recruiter accounts; records are not distinct-person counts.

    [s2]p.1 §1-2 / p.2 §4
  • Reported fact

    The previously contracted ApplyNow platform was accessed without authorization.

    [s3]p.1 §§1-3
  • Reported fact

    313 Kashihara application records may be affected; the count remains provisional. Separately stored images and videos were excluded.

    [s3]p.1 §§1-3
  • Reported fact

    The ApplyNow intrusion leaked Fuji City applicants’ information.

    [s4]10月7日続報 流出した個人情報 / 今後の対応
  • Reported fact

    The follow-up confirmed 815 leaked records, updating the provisional estimate of about 800; videos were excluded.

    [s4]10月7日続報 流出した個人情報 / 今後の対応

Timeline

  1. Event date reported by the source. [s2] [s1]

  2. Disclosure date established by the reviewed notice. [s4]

  3. Disclosure date established by the reviewed notice. [s3]

  4. Disclosure date established by the reviewed notice. [s2]

Reported response

  • Reported fact

    The path was blocked, the vulnerability patched, and affected customers advised to change passwords.

    [s2][s1]p.1 §1-2 / p.2 §4
  • Reported fact

    Applicants will be notified and the vendor’s investigation reviewed.

    [s3]p.1 §§1-3
  • Reported fact

    Affected people were warned and data-management measures are being reviewed with the vendor.

    [s4]10月7日続報 流出した個人情報 / 今後の対応

Evidence relevant to prevention

Insufficient evidence

Undisclosed entry or patch timing prevents an avoidability assessment. Inspect privileges, retrieval logs, retention and deployed configuration using the linked rules.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The reviewed disclosures do not establish attacker use of AI.

Product, CVE, and prior patch timing are undisclosed; similarity to other BI incidents does not establish a shared vulnerability.

The notice does not establish all entry, timing and extraction details; unresolved claims remain unknown.

The October follow-up’s 815 affected people replaces the initial estimate; it is not added to that estimate.

Sources

  1. [s1] ApplyNow · Primary source

    ApplyNow:事故に関する公表資料 ↗

    Published 2026-09-09 · Reviewed 2026-10-09

  2. [s2] 吉野家ホールディングス・吉野家・はなまる · Primary source

    吉野家ホールディングス・吉野家・はなまる:事故に関する公表資料 ↗

    Reviewed 2026-10-09

  3. [s3] ApplyNow(吉野家・橿原市・富士市) · Primary source

    ApplyNow(吉野家・橿原市・富士市):事故に関する公表資料 ↗

    Reviewed 2026-10-09

  4. [s4] ApplyNow(吉野家・橿原市・富士市) · Primary source

    ApplyNow(吉野家・橿原市・富士市):事故に関する公表資料 ↗

    Reviewed 2026-10-09