Chinese eCommerce Breach: 605,932 Shanxiyouche Records on Telegram
In November 2024, HEROIC identified 605,932 records from Shanxiyouche, a Chinese eCommerce platform. The data was posted on a Telegram channel and contained phone numbers, usernames, and SHA1 password hashes.
Why the Shanxiyouche Breach Is Dangerous
With phone numbers, usernames, and SHA1 password hashes from a Chinese eCommerce platform, attackers can crack the SHA1 hashes offline and launch credential stuffing attacks against email, social media, and banking accounts where the same credentials were reused. The phone numbers also enable SMS-based social engineering and SIM swap attacks targeting account recovery.
What Was Exposed in the Shanxiyouche Leak
- Phone numbers
- Usernames
- Password hashes (SHA1)
Why This Shanxiyouche Data Puts You at Risk
SHA1 is a weak hashing algorithm vulnerable to brute force and rainbow table attacks. With over 600,000 phone numbers linked to credentials, attackers can target account recovery systems that rely on phone verification -- making this breach particularly dangerous for any accounts where the same phone number was registered.
How Database Breaches Work
Database breaches occur when attackers exploit vulnerabilities in web applications -- SQL injection, misconfigured access controls, or compromised admin credentials -- to extract the underlying user database. The stolen records are then packaged and distributed on hacking forums or Telegram channels for further exploitation.
Check If Your Data Was Exposed
HEROIC operates one of the world's largest breach databases, covering more than 400 billion leaked records. Use HEROIC's free breach scanner to check if your email address or credentials appeared in the Shanxiyouche leak or thousands of other breaches in our database.
Breach Breakdown
605,932 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds