In my last piece I covered Daiwa Securities losing about 110,000 client records through a hacked vendor's inquiry server, and now the same vendor has taken a second company with it. I run AliasFleet: every account you open gets its own forwarding email address, so a stolen vendor file points straight back at the company that lost it. Citizen Watch disclosed today that unauthorised access to Scala Communications' servers may have leaked up to 100,000 of its customers' personal records.
The vendor is Scala Communications. Citizen outsourced its customer inquiry desk to them, and Scala's servers were hit in the same window as the Daiwa intrusion, the night of October 2 to the morning of October 3. Two companies, two disclosures a day apart, one hacked vendor. You will never get a say in which vendors a company picks, and this is what that costs.
"We were informed by Scala Communications, the provider of the system we use to handle inquiries from the contact forms on our Citizen, Bulova and Frederique Constant brand websites, that unauthorized access to their servers may have led to inquiry information stored in the system, including our customers' data, being improperly obtained. No unauthorized access to our own systems has been confirmed." (Citizen Watch, October 6 notice, translated from Japanese)
What the vendor's file may hold
| May have leaked | Confirmed not affected |
|---|---|
| Name | Citizen's own systems (no intrusion confirmed there) |
| Home address | |
| Phone number | |
| Email address | |
| Bank account or credit card details, if you typed them into the inquiry message field |
The "may have leaked" phrasing is the honest one. Scala's intrusion is confirmed; whether the attacker copied the customer records is not. The scope is stated as a maximum, not a counted exfiltration. Treat the full 100,000 as the working number anyway. That is what the company is doing, and it is the number you should plan around.
Two things make this file worse than Daiwa's. First, the home address. Daiwa's stolen set was names, email addresses and securities account numbers: painful, but not a map to your front door. Citizen's file adds the physical address, which turns phishing into something uglier. A scam email that quotes your home address is hard to dismiss, and it does not take much imagination to see where that goes.
Second, the free-text field. Inquiry forms have a message box, and people write all kinds of things in message boxes when they are trying to get help. Citizen is being honest about this: if you put bank account or credit card details in your message to their support desk, those may be in the file too. That is a genuinely nasty detail, because it means the breach includes data Citizen never asked for and cannot confirm.
What Citizen's own systems look like: the company says no unauthorised access to its systems was confirmed. The intrusion hit the vendor's server. For customers, that distinction changes nothing. Your data was still in the file the attacker reached.
One vendor, two companies
Think about what Scala Communications does. It is the company that answers the phone and the contact form when you have a problem with your watch. Dozens of brands outsource exactly this, because answering customer emails is expensive and unglamorous. The result is a handful of vendors sitting on inquiry records from many brands at once.
Now map the timeline. The night of October 2, an intruder got into Scala's servers. By October 5, Daiwa Securities said up to 110,000 of its clients' records may have leaked through Scala's inquiry-management server. On October 6, Citizen said up to 100,000 of its customers' records may have leaked from Scala's servers. Same vendor, same intrusion window, two client companies, roughly 210,000 records at risk between them.
Here is what bothers me about that. Daiwa's customers and Citizen's customers never chose Scala Communications. They chose a brokerage and a watch company. The vendor was picked for them, the security of the vendor was assessed by someone else, and the contact details they handed over in good faith now sit in a file neither company fully controls. When a single vendor handles many clients' personal data, one intrusion becomes a breach cluster. The customers get the risk and the breach notification; they never got the vendor-selection meeting.
I keep coming back to the structural point I made about this week's Japanese app breaches: you can pick a careful company and still end up in a stolen file. This is the B2B version of the same truth. There is no "careful" choice a customer can make about a vendor they will never meet.
Daiwa Securities disclosed its Scala-linked breach on October 5; Citizen followed on October 6. You cannot know which vendors sit behind the contact forms you fill in, so treat every inquiry-form address as exposed until proven otherwise.
If you used Citizen's contact form
If you emailed Citizen, Bulova, or Frederique Constant through their website contact forms, work from the assumption that your record is in the set. Here is what to do.
- Read any message you sent them as exposed. Pull up the inquiry you submitted if you can. If it contains bank account or card details, act on those first: contact your bank about the exposure, review recent statements, and do not wait for a company notification.
- Expect the address trick. Your home address is in this file. A scam email or letter that quotes your real name and address is designed to survive your first instinct to doubt it. Any message that arrives because of the breach and then asks for passwords, card numbers, or a "verification" transfer is a scam, no matter how much of your data it quotes.
- Treat breach notifications as the next attack wave. When companies notify victims, the attackers know the notification is coming and impersonate it. Go to the company's own site yourself rather than following links in a message.
- Turn on multifactor authentication everywhere it matters. The file has your email address and phone number, which are the two ingredients of most account-recovery flows. MFA is what stands between a leaked contact set and an account takeover.
- Check Have I Been Pwned once the breach is listed. It is the canonical record of which of your addresses have leaked and where.
The breach-response guide walks through all of this in order.
The contact form is where aliases earn their keep
Think about what an inquiry form actually asks for. Your name, your email, your phone number, and then a free-text box where you describe your problem. It is the most trusting interaction on the internet: you are asking a company for help, so you give them everything they ask for, including your real email address.
In practical terms: if the address you gave Citizen's contact form had been an alias used only for Citizen, the email address in the stolen file is a fingerprint: every phishing message that lands on it from now on is either from Citizen or from whoever stole Scala's copy. Pause or delete that alias and the whole attack channel dies, while your real inbox stays clean.
That is the leak-tracing mechanism in practice: the address itself is the receipt. It names the company that handed it to the attacker, and no investigation is required. Contact forms are the perfect use case for it, because they are exactly the place where you hand over real details to companies whose vendors you cannot audit. New to aliases? This is what an email alias is, and the set-up guide takes about two minutes.
Where this goes next
What happens next depends on three things. First, whether Scala Communications has other clients with customer files on the same servers. Daiwa and Citizen are the two we know about; the client list is not public, and one hacked vendor can mean more disclosures this week. Second, whether the attacker actually exfiltrated the data or only reached the servers. Both disclosures say "may have leaked", which is the honest wording for a confirmed intrusion with an unconfirmed copy. Third, whether the file surfaces anywhere public, which would move this from a contained intrusion to a circulating dataset.
Citizen says no secondary misuse has been confirmed. That is a point-in-time finding, not a clean bill of health: a file of names, addresses, phones and emails does not get used on day one. It gets used in the weeks after, when the breach notifications arrive and the impersonators move in. Watch the channel you gave them.

Top comments (0)