Seiko says ransomware attack exposed about 60,000 items of personal data
- Organization
- Seiko Group Corporation
- Exploit
- Ransomware
- Industry
- Manufacturing
Seiko Group Corporation confirmed on October 25, 2023 that a ransomware attack on its network had exposed roughly 60,000 items of personal data held by three of its businesses: Seiko Group Corporation, Seiko Watch Corporation and Seiko Instruments Inc.
The Japanese manufacturer had disclosed on August 10 that an unauthorized party gained access to at least one of its servers on July 28, 2023. The ALPHV group, also known as BlackCat, listed Seiko on its extortion site on August 21 and began publishing samples of stolen material. The October statement was the company's third public report on the incident and the first to quantify the personal data involved.
According to Seiko, the exposed records included names, addresses, telephone numbers and email addresses belonging to Seiko Watch customers; business contact details for people at counterparty companies, covering names, job titles, employers, company addresses, phone numbers and email addresses; information on job applicants, including addresses and educational background; and names and email addresses of current and former employees. Seiko said the credit card details of watch customers were not accessed.
Seiko said it had completed a review with outside cybersecurity specialists, reported the incident to the authorities and begun contacting affected individuals directly. It said it was deploying endpoint detection and multi-factor authentication as part of a wider review of its IT operations.