Security Guides
Seicomart app breach (about 572,000 members): names, addresses and birth dates viewed — what members should do
Unauthorized access to the Seicomart app let a third party view the names, addresses, dates of birth, phone numbers and email addresses of 572,022 members. Based on the operator's official notices: what was and was not exposed, and what members can do today.
For: Seicomart Club members in Japan who have ever registered with the Seicomart app (former members may be included), and anyone who runs a membership app. This article is based on the official notices from Seicomart Co., Ltd. and does not cover attack techniques.
What members should do today
Do not follow links or instructions in emails, texts or calls claiming to be the company
The exposed data combines surname and given name, address, date of birth, phone number and email address. With all of that, a scammer can send a message with the right name and the right address.
If you get a message about "points as an apology", "re-registering your member details" or "checking your Peco Mama Money balance", do not open the link; open the official app yourself or ask in store. Fake text messages (smishing) and phone calls that try to draw out personal details are handled the same way (see What is phishing?).
Never give anyone your PIN, passwords or card details
The company says it will never ask by email for passwords, the Pecoma Card PIN (personal identification number), credit card details or bank details.
A caller who knows your name and date of birth is not proven genuine by that. Those are exactly the details that were viewed.
Stop using your date of birth as a PIN or an identity-check answer
Dates of birth are often used as card PINs, as answers to security questions, and for identity checks by phone. In this incident, the date of birth was viewed together with the address and phone number.
If your Pecoma Card, bank card or any other PIN uses the digits of your date of birth, change it to an unrelated number. If a service lets you set a passphrase or an extra check for phone support, set one.
If you reuse the same password elsewhere, separate them
The company says password data was not leaked and is not asking members to change passwords. Logging in to My Page is also suspended as of October 3.
If you use the same password on other services, though, separate them now. A password manager is the realistic way to do the inventory.
Watch your Peco Mama Money balance for unexpected drops
The company says no misuse of Peco Mama Money has been found so far. Using and topping up Peco Mama Money, earning points and buying at member prices all work as usual.
If you notice a drop in your balance you cannot explain, for example on a receipt, call customer service (0120-89-8551, Monday to Saturday, 9:00–17:00). Use the number on the official website, not one given in a message you received.
What happened (from Seicomart's notices)
Seicomart Co., Ltd. published its first and second notices on September 29, 2026 and a third on September 30. Everything below is as stated in the company's notices.
Sep 24, 2026 (Thu), 22:00–23:00
One account had its Club Card membership cancelled without authorization. No unauthorized cancellations were found on other accounts.Sep 28 (Mon), shortly after 17:00
From that case, the company found that the member server may have been accessed without authorization.Sep 28, 20:00
The connection to the server was stopped. New sign-ups, changes to member details, changes to registered cards, cancellations and My Page logins were suspended.Sep 29
First notice (about 570,000 accounts) and second notice (purchase history not leaked; logins to the online shop and reservation sites suspended).Sep 30
Third notice: the company confirmed that data on 572,022 people was viewed and reported the incident to the authorities under Japan's Act on the Protection of Personal Information.
- Who
- 572,022 people among those who have registered with the Seicomart app. People who never registered with the app are not affected
- Items viewed
- Surname and given name, gender, date of birth, address, phone number, email address, Club Card join date, Club Card leave date
- Not leaked
- Password data and purchase history. The company does not hold credit card data
- E-money
- No misuse of Peco Mama Money found so far
- Cause
- Not disclosed. Under investigation with an outside firm; details withheld because the company is working with the police and other authorities
- Suspended
- New sign-ups and card changes in the app, member-detail changes and cancellations on My Page, the official online shop, the Pecoma Market order site, member login on the product reservation site (restart dates to be announced)
- Still available
- Using and topping up Peco Mama Money, earning points, member prices, coupons and campaigns. New sign-ups and member-detail changes are accepted in store
- Contact
- Seicomart customer service, 0120-89-8551 (Monday to Saturday, 9:00–17:00, Japan)
Notes for members
According to the second notice, points due to expire at the end of September have been extended by one month. Pecoma Market orders can still be placed on the multi-function copy machines in stores. The product reservation site accepts reservations as a guest, without member login.
What the exposed items can be used for in combination
None of these items is rare on its own, but together they become more useful to a scammer. A date of birth known together with an address and phone number in particular makes it easier to pass identity checks at other companies.
Name + address + phone + email
↓→
Scam emails, texts and calls with your correct details
→ Do not open links; check in the official app or in store
Date of birth + address + phone
↓→
Phone identity checks at other companies; birth-date PINs
→ Change the PIN; set a passphrase
Join and leave dates
↓→
Messages that quote your membership history
→ Knowing your history does not make a caller genuine
Not leaked, according to the company
- Password data
- Purchase history
- Credit card data (never held)
Viewed (hard to change yourself)
- Name, gender and date of birth
- Address and phone number (unless you move or change number)
- Email address (changeable, but a hassle)
How to read it: 'no misuse found' does not mean 'safe from now on'
The company says no misuse of Peco Mama Money has been found so far. That means nothing has been found yet, not that the viewed data will never be used.
Addresses and dates of birth do not change over time, so they can be used in scam messages months or years later. Stay alert to messages that use this incident as a reason to contact you.
The leave date is among the exposed items, and the notice describes the affected people as members who "have registered" with the app. Records of people who have already left may be included, so it is worth going through the steps above even if you no longer use the app. For the Japanese privacy-law rules on requesting that a business stop using or delete your data, see the Times Car breach.
For those who run membership apps
According to the notice, the access went through the app's server to the server holding member data. The specific method has not been disclosed, so this section sticks to points that any service with the same setup can review.
Limit what the app's server can read from the member database
An app screen usually needs only the signed-in member's own data. Check whether the app's server has permission to read every member's address and date of birth at once.
Set limits on both the app side and the database side: return no records other than the member's own, and cap how many records one request can return (background: Authentication vs. authorization).
Be able to notice unusual operations that change a member's status
The incident came to light because one account's membership was cancelled without authorization. Operations that change a member's status — cancellation, changing a registered card, changing contact details — are rare, so unusual activity stands out.
A first step is to record how many of these operations happen per hour and notify someone when the count reaches several times the usual level. Setting limits and alerting when they are reached is covered in Rate limiting and abuse control.
Decide how long to keep former members' personal data
List which items must be kept, and for how long, for legal or accounting reasons, and have everything else deleted automatically a set period after the member leaves. Manual deletion does not last.
For a comparison with other major Japanese breaches disclosed the same year, see Japan's major data breaches of 2026.
Sources (public record)
The facts in this article come from the public sources below. Undisclosed methods or causes of the intrusion are not speculated on.
- Seicomart Co., Ltd., apology and notice on the possible leak of personal data from unauthorized access to the Seicomart app (first notice, September 29, 2026, Japanese) — secoma.co.jp (PDF)
- Same (second notice, September 29, 2026: purchase history not leaked; online shop and reservation sites suspended, Japanese) — secoma.co.jp (PDF)
- Same (third notice, September 30, 2026: 572,022 people confirmed viewed; report to the authorities, Japanese) — secoma.co.jp (PDF)
- Secoma official website, notices page listing the first to third notices (Japanese) — secoma.co.jp
- INTERNET Watch, report on the possible leak of about 570,000 accounts' member data (September 29, 2026, Japanese) — internet.watch.impress.co.jp
Update history
2026-10-03: First version, based on Seicomart's first and second notices (September 29) and third notice (September 30). The company says it will announce the cause, prevention measures and restart dates for suspended services later; this article will be updated when it does.
Read next
- Follow-on scams: What is phishing? / Smartphone security basics / Fake virus warnings (tech-support scams)
- Passwords: Choosing a password manager / Choosing multi-factor authentication
- Other Japanese incidents at the same time: The Times Car breach / Japan's major data breaches of 2026
- Other 2026 incidents: list of breaches and cyberattacks (Japan and worldwide)
- For operators: The minimum security baseline for organizations
FAQ
QWhat was exposed in the Seicomart app breach?
According to Seicomart Co., Ltd.'s third notice on September 30, 2026, the company confirmed that data on 572,022 people who had registered with the app was viewed. The items are surname and given name, gender, date of birth, address, phone number, email address, and the dates the person joined and left the Club Card program (first notice, September 29).
QWhat was not exposed?
The company says password data and purchase history were not leaked, and that it does not hold credit card data. For the Peco Mama Money e-money service, it says no misuse has been found so far.
QAm I affected?
According to the third notice, the affected people are 572,022 of those who have registered with the Seicomart app (49% of app members). People who never registered with the app, and people registered only with the official online shop who hold no member card (physical card or app), are not affected. Because the exposed items include the date the person left the program, records of former members may also be included. As of October 3, the company had not described a way to check individually whether you are affected.
QShould I change my password?
The company says password data was not leaked and is not asking members to change passwords. Logging in to My Page is also suspended for now. If you use the same password on other services, though, this is a good moment to stop reusing it.
QWhat scams should I watch for?
Because name, address, date of birth, phone number and email address were exposed together, convincing emails, texts and calls posing as the company are possible. The company says it will never ask by email for passwords, the Pecoma Card PIN, credit card details or bank details. Do not open links in such messages; check through the official app, in store, or with the customer service line (0120-89-8551, Monday to Saturday, 9:00–17:00, Japan).
QWhat caused the breach?
As of October 3, 2026, the method of the unauthorized access had not been disclosed. The company is investigating with an outside firm and says it is withholding details because it is working with the police and other authorities. It says it will publish the cause and recurrence-prevention measures on its website once they are known.