applynow-bi-2026 · Disclosed 2026-09-09
ApplyNow(吉野家・橿原市・富士市): unauthorized access and impact
A vulnerability in outsourced ApplyNow analytics was exploited; applicant data remained after contract termination. Scope includes 4,998 Yoshinoya applications, 368 Hanamaru applications, and 418 recruiter accounts; records are not distinct-person counts. The previously contracted ApplyNow platform was accessed without authorization. 313 Kashihara application records may be affected; the count remains provisional. Separately stored images and videos were excluded. The ApplyNow intrusion leaked Fuji City applicants’ information. The follow-up confirmed 815 leaked records, updating the provisional estimate of about 800; videos were excluded.
Outcome: Confirmed breach
Entry path and evidence
- Reported fact
A vulnerability in outsourced ApplyNow analytics was exploited; applicant data remained after contract termination.
- Reported fact
Scope includes 4,998 Yoshinoya applications, 368 Hanamaru applications, and 418 recruiter accounts; records are not distinct-person counts.
[s2]p.1 §1-2 / p.2 §4 - Reported fact
The previously contracted ApplyNow platform was accessed without authorization.
[s3]p.1 §§1-3 - Reported fact
313 Kashihara application records may be affected; the count remains provisional. Separately stored images and videos were excluded.
[s3]p.1 §§1-3 - Reported fact
The ApplyNow intrusion leaked Fuji City applicants’ information.
[s4]10月7日続報 流出した個人情報 / 今後の対応 - Reported fact
The follow-up confirmed 815 leaked records, updating the provisional estimate of about 800; videos were excluded.
[s4]10月7日続報 流出した個人情報 / 今後の対応
Timeline
Reported response
- Reported fact
The path was blocked, the vulnerability patched, and affected customers advised to change passwords.
- Reported fact
Applicants will be notified and the vendor’s investigation reviewed.
[s3]p.1 §§1-3 - Reported fact
Affected people were warned and data-management measures are being reviewed with the vendor.
[s4]10月7日続報 流出した個人情報 / 今後の対応
Evidence relevant to prevention
Insufficient evidence
Undisclosed entry or patch timing prevents an avoidability assessment. Inspect privileges, retrieval logs, retention and deployed configuration using the linked rules.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The reviewed disclosures do not establish attacker use of AI.
Product, CVE, and prior patch timing are undisclosed; similarity to other BI incidents does not establish a shared vulnerability.
The notice does not establish all entry, timing and extraction details; unresolved claims remain unknown.
The October follow-up’s 815 affected people replaces the initial estimate; it is not added to that estimate.
Sources
[s1] ApplyNow · Primary source
ApplyNow:事故に関する公表資料 ↗Published 2026-09-09 · Reviewed 2026-10-09
[s2] 吉野家ホールディングス・吉野家・はなまる · Primary source
吉野家ホールディングス・吉野家・はなまる:事故に関する公表資料 ↗Reviewed 2026-10-09
[s3] ApplyNow(吉野家・橿原市・富士市) · Primary source
ApplyNow(吉野家・橿原市・富士市):事故に関する公表資料 ↗Reviewed 2026-10-09
[s4] ApplyNow(吉野家・橿原市・富士市) · Primary source
ApplyNow(吉野家・橿原市・富士市):事故に関する公表資料 ↗Reviewed 2026-10-09