← Blog

Seicomart Breach: ~570K Club App Accounts Hit 2026

Share on X

About 570,000 Seicomart Club loyalty accounts may already have had their profile fields browsed by someone who was not supposed to see them. On 29 September 2026, Hokkaido-centered convenience chain Seicomart Co., Ltd. (セイコーマート) confirmed that unauthorized access through its smartphone Seicomart app reached a member-information server — and that name, gender, date of birth, address, phone, email, and club join/leave dates for roughly 570,000 user IDs may have been viewed. ASCII.jp summarized the notice the same morning; the company’s own apology also went out on @Seicomart_TW.

This is a verified company disclosure, not a leak-site rumor. Seicomart says passwords were not leaked, it does not store credit-card numbers for this Club corpus, and it has not seen misuse of Peko Mama Money (ペコママネー) e-money so far. Canonical BreachHistory record: https://breachhistory.com/seicomart/seicomart-app2026.

Late September 2026 already produced other Japanese customer-data headlines — Tokyo Metro’s Metpo email exposure and Park24’s Times Car incident among them. Useful calendar context. Not evidence that Seicomart shares an actor, tooling, or campaign with those events. Keep each company’s notice on its own shelf.

What Seicomart said happened

Strip the apology language and the sequence is concrete. On the evening of Thursday, 24 September 2026, between roughly 22:00 and 23:00, staff spotted one unauthorized Club card cancellation. That odd withdrawal kicked off a deeper look. By Monday, 28 September 2026, shortly after 17:00, investigators concluded that a third party had likely reached the server holding Club member information via the Seicomart app’s server path. The company says it has not found similar unauthorized cancellations on other accounts.

Containment followed the same day. At about 20:00 on 28 September, Seicomart disconnected that member server. With the link down, several customer-facing Club functions went offline: new membership registration, member-profile edits, registered-card changes, voluntary cancellation, and My Page login. The public apology dated 29 September 2026 then put the ~570,000 figure and the field inventory in front of members and the press.

What public reporting has not supplied is a CVE number, a named malware family, a ransomware brand, a dump mirror, or a minute-by-minute intrusion timeline beyond those two calendar anchors. Absence of those extras is an early forensics gap, not silence about the breach itself. Seicomart said it will keep investigating root cause and recurrence controls and publish findings on its site and SNS when ready.

What was exposed — and what was not

Attested inventory from the company for the ~570,000 possibly affected user IDs:

  • Name (姓名)
  • Gender
  • Date of birth
  • Address
  • Phone number
  • Email address
  • Club card join date and leave/cancellation date

Explicitly not in the exposure set, per Seicomart:

  • Passwords — the company states they were not leaked.
  • Credit-card numbers — the company says it does not hold them for this Club data store.
  • Confirmed Peko Mama Money misuse — none observed at the time of the notice.

That split matters. A name-plus-address-plus-phone-plus-email roster for more than half a million convenience-store loyalty members is a serious identity and fraud event in Japan — large enough to fuel SMS and email lures that sound like a real Seicomart Club notice — without matching the blast radius of a password-hash dump or a card-PAN breach. Do not inflate this into “every payment instrument at every Seicomart till was stolen.” Do not shrug because “passwords survived.”

One operational nuance: the first visible symptom was a single unauthorized Club card cancellation, not a mass withdrawal wave. Seicomart says other accounts did not show the same fake-cancellation pattern. That is reassuring for people who still see an active Club status in-store. It does not shrink the ~570,000 “may have been viewed” census for profile fields on the member server.

How the access is described (without inventing a PoC)

Public sources stay in institutional language: unauthorized access to the member-information server via the Seicomart app’s server, discovered while chasing one bad cancellation, then severed the same evening. That is enough to classify the row as unauthorized access against Club member infrastructure tied to the smartphone app path. It is not enough to invent VPN MFA bypass, SSO token theft, upload RCE, or a specific bug class.

Defenders can still take concrete lessons without a PoC. A single anomalous loyalty-cancellation event can be the first symptom of hostile reach into a member store. App-fronted member APIs deserve the same monitoring intensity as POS or e-money rails. Disconnecting a member server buys containment time — and immediately breaks new joins, profile edits, and My Page — which is exactly what Seicomart chose. Closing the pipe does not erase copies already taken. Do not invent malware family names absent from the notice. Update later from Seicomart’s own follow-up, not forum speculation.

Who is at risk

Seicomart Club members in the ~570,000 set

If you hold a Seicomart Club membership tied to the smartphone app, treat possible viewing of your name, gender, DOB, home address, phone, email, and Club tenure dates as the working assumption until the company narrows the set. Seicomart’s footprint is strongest in Hokkaido, with presence also in parts of the Kanto region — so the affected population is not “all of Japan’s convenience shoppers,” but it is a large slice of a regional loyalty base that shops daily for food, bill pay, and small errands.

You do not need a public paste site to raise defenses. Full postal addresses plus phones and emails are enough for targeted SMS about “Club re-registration after the app incident,” fake My Page unlock pages, and phone calls that recite your real neighborhood to sound official.

Peko Mama Money / e-money users

Seicomart says it has not confirmed unauthorized use of Peko Mama Money so far, and it will never ask by email for a Peko Mama card PIN, password, credit-card number, or bank details. Still watch transaction history if you load e-money through the brand. A clean misuse statement today is not a lifetime warranty that social engineers will stay away from Peko Mama-branded lures tomorrow.

Everyone else watching the headline

People who only buy cash snacks at Seicomart without a Club account are outside this notice’s attested census — still ignore brand-wide phishing that invents exposure for non-members. Household members who share an email or phone with a Club holder inherit some of the social-engineering risk. Store staff and app vendors should treat “reset Seicomart admin credentials after the breach” mails that demand passwords or remote tools as social engineering unless verified out-of-band.

Industry context: Japan retail loyalty apps in late 2026

Japanese convenience and mobility brands stack member PII behind smartphone apps for points, coupons, and e-money. When that app path can reach a member server, one unauthorized session can touch hundreds of thousands of profiles. Late September 2026 already put Tokyo Metro’s Metpo email exposure and large car-sharing disclosures into the same news cycle — useful calendar context, not a shared-attacker claim.

Convenience retail sits next to everyday fraud economics: bill-pay counters and e-money top-ups. Attackers who hold name + address + phone do not need your Club password to sell a convincing “your Seicomart Club was cancelled — rejoin here” story. Local trust in Hokkaido makes spoofed “お詫び” emails more believable, not less. Peer operators should alert on anomalous loyalty-cancellation events and ask whether app tiers can reach full member PII without step-up controls — design questions Seicomart’s notice implies without answering yet.

What the company told members to do

Seicomart’s 29 September apology is unusually clear about fraud hygiene:

  • Watch for emails that impersonate Seicomart after this incident.
  • The company will never ask by email for passwords, Peko Mama card PINs, credit-card numbers, or deposit/bank details.
  • Peko Mama Money misuse had not been confirmed at notice time.
  • Root cause and recurrence measures remain under investigation; updates will go to the official site and SNS when ready.
  • Questions can go to the Seicomart customer consultation desk at 0120-89-8551 (Monday–Saturday, 9:00–17:00).

Use that guidance. An email asking you to “verify on this .xyz domain,” “unlock My Page via remote support software,” or “send your Peko Mama PIN to restore Club points after the unauthorized access” fails the company’s own published test.

Timeline readers can use

  • 24 September 2026, ~22:00–23:00: One unauthorized Club card cancellation is detected; investigation begins.
  • 28 September 2026, ~17:00: Company concludes unauthorized access to the member-information server (via the Seicomart app server path) likely occurred; no similar fake cancellations found on other accounts.
  • 28 September 2026, ~20:00: Member server connection stopped; new joins, profile/card changes, cancellations, and My Page login suspended.
  • 29 September 2026: Seicomart publishes the apology describing ~570,000 possibly affected Club user IDs, the viewed-field list, password/card limits, and the Peko Mama Money status; ASCII.jp and regional press (including Yahoo/HBC-style coverage) carry the same core facts.
  • 29 September 2026 (this post): BreachHistory indexes the verified disclosure with the ~570,000 count and field inventory.

Exact first-access timestamps before the 24 September cancellation signal, attacker tooling, and whether any profiles were posted publicly were not in the company notice at indexing. Do not invent them.

Was I affected by the Seicomart Club app breach?

Short answer: if you are a Seicomart Club member among the roughly 570,000 user IDs the company flagged, treat compromise of the listed profile fields as possible. There is no public self-serve “check my Club ID” census in the sources used here beyond the company’s aggregate figure and the suspended My Page path.

Practical checks:

  1. Watch official Seicomart channels and the published customer desk number — not Gmail lookalikes or “[email protected].”
  2. If My Page login is still suspended when you try, that matches the company’s containment story; do not “fix” it through a third-party unlock site.
  3. Ignore dump-checker sites that demand your Club ID, phone, or card to “search the Seicomart leak.” Sites asking for more than the company listed are often the scam.
  4. If you never joined Seicomart Club, this notice is not describing your cash purchases — still ignore brand-wide phishing that pretends otherwise.
  5. Remember: “may have been viewed / may have leaked” is the company’s careful phrasing. Plan defenses as if the profile fields left; do not wait for a paste-site screenshot.

Phishing and fraud patterns to expect

Concrete themes to reject after this Seicomart data breach coverage:

  • “Seicomart Security: re-verify your Club membership after the unauthorized access — enter password and SMS code here.”
  • “Your Club card was cancelled (like the Sep 24 incident) — reopen My Page on this external form today.”
  • “Seicomart IT: install this remote tool so we can check whether your ID was in the 570,000.”
  • “Send your Peko Mama PIN / credit-card number / bank details to freeze fraudulent charges after the app hack.” (Company says it never asks for those by email.)
  • “We found your Seicomart address in a dark-web dump — pay crypto for takedown.”
  • Messages that mash Seicomart with unrelated late-September Japan breach headlines into one “all convenience chains must reset payment methods” scare story.
  • Calls that recite a plausible Hokkaido or Kanto store name and ask for a one-time banking code “to secure your Club after the leak” when card PANs were not in the attested store.

Legitimate remediation points at known Seicomart channels and the published inquiry phone hours. It will not demand crypto, remote-access software, or card PANs as a condition of “securing your Club account after the breach.”

What you should do

  1. Club members: Assume name, gender, DOB, address, phone, email, and Club tenure dates may be with whoever reached the member server if you are in the ~570k set. Brief household members about fake Club and Peko Mama messages.
  2. Treat official contact carefully: Prefer the published desk 0120-89-8551 (Mon–Sat 9:00–17:00) and Seicomart’s own site/SNS over unsolicited email links.
  3. Password hygiene: Even though Seicomart says Club passwords were not leaked, rotate any password you reused on email or other sites if the same string lived near your Club login habit, and turn on MFA on the inbox attackers will target next.
  4. Watch Peko Mama Money: Monitor e-money activity as ordinary hygiene; do not treat the notice as confirmed e-money theft when the company says misuse was not seen — and still reject PIN-harvesting mail.
  5. Address/phone exposure: Expect more convincing SMS and voice lures that know your real neighborhood; verify out-of-band before sharing codes.
  6. Employees and vendors: Freeze unusual “update Seicomart app credentials after the incident” requests; call back on numbers you already trust.
  7. Do not download alleged “Seicomart proof packs” from forums — often malware or unrelated dumps.
  8. Do not pay takedown vendors claiming they can scrub your profile from a leak that may not be public.
  9. Do not conflate Tokyo Metro Metpo or Times Car notices with Seicomart Club guidance; follow each operator’s own page.
  10. Security teams at peer retailers: Alert on single anomalous loyalty-cancellation events; inventory whether app tiers can reach full member PII; plan customer messaging for My Page outages before the next incident.
  11. Watch official channels for a later cause write-up or expanded scope; update FAQs from Seicomart’s own posts, not from rumor screenshots.

Why passwords surviving still leaves a real breach

It is tempting to rank any retail story that ends with “passwords not leaked, no cards stored, no e-money misuse confirmed” as a minor hiccup. That undersells the fraud economics. Name, date of birth, address, phone, and email tied to a trusted Club brand are pre-authenticated social-engineering hooks — especially when My Page is confirmed offline the same week as an ASCII.jp headline.

Seicomart’s disclosure separates questions shoppers mash together: (1) Were Club profile fields viewed? (2) Was my password taken? (3) Were cards or Peko Mama balances drained? On current evidence: (1) about 570,000 user IDs may have had the listed PII viewed; (2) passwords were not leaked; (3) cards are not held and Peko Mama misuse was not confirmed. Inflating this into card-theft theatre helps scammers. Shrugging because “passwords survived” helps phishers who only needed the address book.

Verified notice, not a thin claim

Some 2026 retail stories remain unverified actor claims. Seicomart is different: a dated company apology with a clear timeline (24 September cancellation signal → 28 September discovery and disconnect → 29 September public notice), a ~570,000 user-ID census, an explicit field inventory, password and card limits, a Peko Mama Money status line, and a published inquiry phone. This post refuses to invent malware names, dump URLs, or payment-card theft the company has not described. Defence is scepticism plus verification against Seicomart’s own channels — and keeping other late-September Japan incidents on separate shelves.

Canonical record and sources

BreachHistory indexes this incident at https://breachhistory.com/seicomart/seicomart-app2026 (relative: /seicomart/seicomart-app2026): Seicomart confirmed roughly 570,000 Club app account IDs may have had name, gender, DOB, address, phone, email, and Club join/leave dates viewed after unauthorized access via the Seicomart app server path; passwords not leaked; credit cards not stored; Peko Mama Money misuse not confirmed; discovery after a 24 September unauthorized cancellation; member server disconnected 28 September ~20:00 with registration/profile/My Page functions suspended; companyConfirmed true; recordsAffected 570000.

Primary sources for this write-up:

Bottom line: Seicomart confirmed a late-September 2026 Club app incident in which about 570,000 member accounts may have had core profile fields viewed after unauthorized access found while investigating a single 24 September fake cancellation; the company says passwords were not leaked, cards are not stored, Peko Mama Money misuse was not seen, and My Page-related functions stay offline while root-cause work continues — members should use the published inquiry desk and reject any email that asks for passwords, PINs, or bank details.