2026 Seiko USA — website defacement; hacker claims full Shopify customer DB (Apr)
Data compromised
E-commerce customer PII and order metadata if claims are authentic—verification pending
Technical writeup
In mid–April 2026, attackers defaced a portion of the Seiko USA public website (e.g., “Press Lounge” sections described in roundups) and claimed to have exfiltrated the organization’s entire Shopify e-commerce customer database, demanding ransom within a short deadline and threatening to leak names, emails, phones, shipping addresses, and order history. PrivacyGuides and TechRadar–style summaries noted Seiko had not fully confirmed the data theft at roundup time and that defaced content was taken down. The incident is distinct from parent Seiko Group’s broader corporate structure but affects the U.S. consumer-facing brand.
Root cause
Website compromise and alleged e-commerce backend access (method not fully confirmed publicly)
References
- https://www.privacyguides.org/news/2026/04/24/data-breach-roundup-apr-17-23-2026/
- https://www.techradar.com/pro/security/hacked-hacker-defaces-seiko-usa-website-and-claims-theft-of-entire-customer-database-heres-what-we-know
- https://www.scworld.com/brief/seiko-usa-website-defaced-customer-data-breach-claimed
- https://www.macken.xyz/2026/04/seiko-usa-website-defaced-as-hacker-claims-customer-data-theft/