A serious cybersecurity incident appears to have hit the Seiko USA website over the weekend, when unknown attackers the website and posted a ransom note. Visitors to the “Press Lounge” section were not presented with the company’s regular content, but instead a page titled “HACKED,” which contained claims of a data breach and ransom demands.

The incident highlights once again the growing threats facing large commercial platforms, particularly when they rely on third-party services to manage their online stores.
The attackers' claims and the data allegedly stolen
According to the message displayed on the compromised page, the attackers claimed to have gained access to the backend of the Shopify used by the company. They said they were able to bypass security measures and extract the entire customer database.
See also: KelpDAO: Are Lazarus hackers behind the recent hack?
The data allegedly compromised includes personal information such as names, email addresses and phone numbers, as well as more complex information such as order history, transaction details and shipping data. In addition, the attackers claim to have gained access to account detailssuch as creation dates and internal customer notes.
If these allegations are confirmed, this is a significant breach that could affect a large number of users, with potential consequences for both their privacy and financial security.
Ransom demand and time ultimatum
The perpetrators did not limit themselves to making their claims public, but also made a clear ransom demand. Specifically, they gave the company 72 hours to contact them and start negotiations, otherwise they threatened to make the data public.

As a means of communication, they pointed to a specific customer account within the Shopify system, to which they allegedly added their own email address. The choice of this method indicates a more targeted and perhaps more sophisticated extortion approach, aimed at proving that the attackers do indeed have access to internal systems.
Seiko USA: Uncertainty surrounding the validity of the attack
So far, the identity of the perpetrators has not been confirmed, nor has it been proven whether their claims correspond to reality. The absence of clear evidence leaves open the possibility of either a real leak or an attempted blackmail without substantial access to critical data.
See also: Scattered Spider: Leading member pleads guilty
The company has not issued an official statement regarding the incident, and the message in question has already been removed from the site. This silence, while common in the early stages of an investigation, intensifies the uncertainty and concerns of users.
The bigger picture of cybersecurity in e-commerce
This incident is part of a broader trend of increasing attacks on e-commerce platforms. Cybercriminals are increasingly targeting companies that handle large volumes of personal data, knowing that pressure to avoid disclosure could lead to ransom payments.
At the same time, reliance on platformslike Shopify creates additional vulnerabilities. Even if the platform itself is secure, configuration errors, weak passwords , or compromised admin accounts can open the door to attacks.
See also: Attackers are abusing Microsoft Teams and targeting employees
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

What businesses and users should pay attention to
For businesses, the incident serves as a reminder of the need for multi-layered security, regular audits, and prompt incident response. The use of strong authentication, staff training , and continuous system monitoring are critical elements.
From the users' perspective, vigilance: changing passwords, avoiding reusing them and paying attention to suspicious messages that may exploit stolen data for phishing attacks.
The Seiko USA incident, regardless of its ultimate outcome, highlights that cybersecurity remains one of the most critical issues of the digital age and requires continued investment and adaptation.
Source: www.bleepingcomputer.com
