Seiko USA website defaced as hacker claims customer data theft

Seiko USA website defaced as hacker claims customer data theft News

Seiko

The Seiko USA website was defaced over the weekend, displaying a message from attackers claiming they stole its Shopify customer database and threatening to leak it unless a ransom is paid.

Visitors to the “Press Lounge” section of the site were shown a page titled “HACKED,” which replaced normal content with what appeared to be a ransom demand and data breach notification. 

The message warned that attackers had gained access to the company’s Shopify backend and exfiltrated sensitive customer information.

image

“This is an urgent security notification regarding your Shopify store. Your customer database has been compromised,” read the defaced webpage.

“We have successfully breached your Shopify store’s security systems and downloaded the entire customer database.”

Seiko website defaced to show extortion message
Seiko website defaced to show extortion message
Source:

The threat actors claim the stolen data contains the following information:

  • Customer Information: Names, email addresses, phone numbers
  • Order History: Purchase records, transaction details
  • Shipping Data: Addresses, shipping preferences
  • Account Details: Account creation dates, customer notes

The attackers warn that the stolen data will be publicly released unless Seiko USA enters into negotiations.

As part of the demand, they instructed the company to locate a specific customer account, identified as ID 8069776801871, within the Shopify admin panel. The threat actors say that a contact email address was added to that account profile and should be used to initiate negotiations.

The defacement further warned that Seiko USA had 72 hours to contact them or the alleged database would be published.

has not been able to determine what threat actor is behind the attack and whether their claims are legitimate.

Seiko USA has not publicly confirmed or responded to emails about the incident, but has since removed the extortion message from the website.

.article-callout {
background-color: #f0f6ff;
width: 95%;
max-width: 800px;
margin: 15px auto;
border-radius: 8px;
border: 1px solid #d6ddee;
display: flex;
align-items: stretch;
overflow: hidden;
}

.article-media {
flex: 1;
max-width: 220px;
display: flex;
}

.article-media a {
display: flex;
width: 100%;
height: 100%;
}

.article-media img {
width: 100%;
height: 100%;

border-radius: 8px 0 0 8px;
display: block;
}

.article-callout .article-media img {
margin-top: 0 !important;
height: 100% !important;
}

.article-body {
flex: 2;
padding: 10px;
display: flex;
flex-direction: column;
justify-content: center;
}

.article-body h2 {
font-size: 17px !important;
font-weight: 700;
color: #333;
line-height: 1.4;
font-family: Georgia, “Times New Roman”, Times, serif;
margin: 0 0 14px 0;
}

.article-body p {
font-weight: bold;
font-size: 14px;
margin: 0 0 clamp(6px, 2vw, 14px) 0;
}

.article-link {
background-color: #fff;
border: 1px solid #3b59aa;
color: black;
text-align: center;
text-decoration: none;
border-radius: 8px;
display: inline-block;
font-size: 16px;
font-weight: bold;
padding: 10px 20px;
width: fit-content;
}

@media (max-width: 600px) {
.article-callout {
flex-direction: column;
align-items: center;
}

.article-media {
max-width: 100%;
}

.article-media img {
border-radius: 8px 8px 0 0;
}

.article-body {
padding: 15px;
width: 100%;
}

.article-link {
width: 100%;
margin: 0 auto;
box-sizing: border-box;
}
}


article image

99% of What Mythos Found Is Still Unpatched.

AI chained four zero-days into one exploit that bypassed both renderer and OS sandboxes. A wave of new exploits is coming.

At the Autonomous Validation Summit (May 12 & 14), see how autonomous, context-rich validation finds what’s exploitable, proves controls hold, and closes the remediation loop.

Claim Your Spot

Comments

Copied title and URL