Seiko USA website defaced as hacker claims customer data theft
好的,我现在需要帮用户总结一篇文章的内容,控制在100字以内。首先,我得仔细阅读文章,理解主要信息。 文章讲的是Seiko USA的网站被黑了,显示了一个黑客的信息。黑客声称窃取了Shopify的客户数据库,并威胁如果不支付赎金就会泄露数据。他们展示了“HACKED”的页面,警告已经访问了后端并下载了敏感信息。被窃取的数据包括客户姓名、邮箱、电话、订单记录、地址等。黑客给了72小时让公司联系他们,否则就公开数据。BleepingComputer无法确认攻击者身份和威胁的真实性,Seiko USA也没有回应。 接下来,我需要把这些信息浓缩到100字以内。要抓住关键点:网站被黑、数据被盗、威胁泄露、赎金要求、涉及的数据类型、时间限制以及公司未回应。 可能的结构是:先说明事件,然后描述黑客的要求和威胁,接着提到数据内容和时间限制,最后提到公司的反应情况。 检查一下字数是否符合要求,并确保没有遗漏重要信息。 </think> Seiko USA网站被黑,显示黑客窃取Shopify客户数据库并威胁泄露以索要赎金。页面警告已访问后端并下载敏感信息,包括姓名、邮箱、电话、订单记录等。黑客要求72小时内联系,否则将公开数据。Seiko USA未回应事件。 2026-4-20 18:31:2 Author: www.bleepingcomputer.com(查看原文) 阅读量:16 收藏

Seiko

The Seiko USA website was defaced over the weekend, displaying a message from attackers claiming they stole its Shopify customer database and threatening to leak it unless a ransom is paid.

Visitors to the "Press Lounge" section of the site were shown a page titled "HACKED," which replaced normal content with what appeared to be a ransom demand and data breach notification. 

The message warned that attackers had gained access to the company's Shopify backend and exfiltrated sensitive customer information.

Wiz

"This is an urgent security notification regarding your Shopify store. Your customer database has been compromised," read the defaced webpage.

"We have successfully breached your Shopify store's security systems and downloaded the entire customer database."

Seiko website defaced to show extortion message
Seiko website defaced to show extortion message
Source: BleepingComputer

The threat actors claim the stolen data contains the following information:

  • Customer Information: Names, email addresses, phone numbers
  • Order History: Purchase records, transaction details
  • Shipping Data: Addresses, shipping preferences
  • Account Details: Account creation dates, customer notes

The attackers warn that the stolen data will be publicly released unless Seiko USA enters into negotiations.

As part of the demand, they instructed the company to locate a specific customer account, identified as ID 8069776801871, within the Shopify admin panel. The threat actors say that a contact email address was added to that account profile and should be used to initiate negotiations.

The defacement further warned that Seiko USA had 72 hours to contact them or the alleged database would be published.

BleepingComputer has not been able to determine what threat actor is behind the attack and whether their claims are legitimate.

Seiko USA has not publicly confirmed or responded to BleepingComputer emails about the incident, but has since removed the extortion message from the website.

tines

99% of What Mythos Found Is Still Unpatched.

AI chained four zero-days into one exploit that bypassed both renderer and OS sandboxes. A wave of new exploits is coming.

At the Autonomous Validation Summit (May 12 & 14), see how autonomous, context-rich validation finds what's exploitable, proves controls hold, and closes the remediation loop.


文章来源: https://www.bleepingcomputer.com/news/security/seiko-usa-website-defaced-as-hacker-claims-customer-data-theft/
如有侵权请联系:admin#unsafe.sh