Seiko USA removed an extortion message after attackers defaced part of its website, reportedly in the Press Lounge section, and claimed they had breached the company’s Shopify backend and stolen customer data. The message alleged the theft of names, email addresses, phone numbers, order history, shipping information, and account details, and threatened to publish the data unless the company negotiated within 72 hours using a contact email allegedly planted in a Shopify customer account.
Independent confirmation of the claimed data theft has not emerged, and Seiko USA had not publicly confirmed a breach at the time of reporting. Coverage from multiple outlets established that the defacement and ransom demand occurred, but the identity of the threat actor and the validity of the exfiltration claims remain unverified.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
Adaptavist warned customers that an unknown third party was sending misleading messages while impersonating the company following the incident. The activity suggested possible follow-on phishing tied to the breach.
A ransomware group calling itself The Gentlemen claimed responsibility for the Adaptavist incident on its leak site, alleging theft of customer records, source code, credentials, internal documents, and access to production systems. Adaptavist disputed those claims and said it had no evidence supporting such a broad compromise.
By the time of reporting, Seiko USA had removed the extortion message from its website. The company had not publicly confirmed the alleged breach or responded to media inquiries, and the attackers' data-theft claims remained unverified.
Over the weekend before April 20, attackers defaced Seiko USA's website, placing an extortion message in the Press Lounge section. The message claimed the attackers had breached Seiko USA's Shopify backend and stolen customer database information, threatening to publish it within 72 hours unless the company negotiated.
Adaptavist published a notice about the March 2026 security incident, stating its current assessment found access to systems containing typical business data such as contact information, contracts, and NDAs. It said there was no evidence at that time that customer or partner personal data had been exfiltrated or that client or production systems were affected.
The Adaptavist Group said it discovered a security incident in late March 2026 in which an attacker used stolen credentials to gain unauthorized access to some of its systems. The company began investigating the incident with external security specialists.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcego.theregister.com
Open sourceteiss.co.uk
Open sourcebleepingcomputer.com
Open sourcetheadaptavistgroup.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.