Inside the SF Express Database Breach: How 35.5 Million Records Were Stolen
HEROIC analysts identified a large-scale database breach affecting SF Express (ShunFeng), one of China's leading courier and delivery services companies. The data surfaced on September 4, 2024, exposing 35,582,351 records. The breach contains customer contact and identity information that links directly to package recipients and senders across China.
Over 35 million people having their names and phone numbers exposed in a single breach creates an enormous pool of verified contact information for attackers. Criminals can use this data to run parcel delivery scams, impersonating SF Express via phone or SMS to trick victims into providing payment information or clicking malicious links. The combination of real names and verified phone numbers makes these impersonation attempts highly convincing and difficult for recipients to detect.
What Was Exposed
- Phone Number
- First Name
- Last Name
Why This Matters
Phone numbers tied to real full names are among the most valuable data points for fraud operations targeting individuals. Delivery-themed scams are a documented and growing attack category, where victims receive calls or messages claiming a package requires additional fees or customs clearance. With real customer names from an actual courier database, attackers can make these communications appear entirely legitimate. Beyond scams, verified phone numbers enable SIM-swapping attacks that defeat two-factor authentication on banking and email accounts. At a scale of 35 million records, this breach gives attackers a ready-made targeting list for mass fraud campaigns across China.
How Database Breaches Work
A database breach occurs when attackers gain unauthorized access to a company's data storage systems. For large logistics companies, customer databases track shipments and contain personal contact information for millions of senders and recipients. Attackers typically gain access by exploiting vulnerabilities in web-facing applications, using stolen credentials, or targeting poorly secured database servers. Once inside, they extract large tables of customer records and transfer them to external systems. These datasets are later posted or sold on dark web forums, often years after the original compromise, meaning the breach discovered in September 2024 may have originated from an earlier intrusion.
Check If You Are Affected
If you have used SF Express for shipping or receiving packages, your name and phone number may be part of this breach. HEROIC's free breach scanner checks your information against more than 400 billion exposed records across thousands of known breaches. Visit heroic.com to check your exposure and find out what steps to take to protect your accounts and identity.
Breach Breakdown
35,582,351 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds