Skip to content
>_ITDITDWeb Security Platform

Security Guides

The appliance you bought years ago left your address with the distributor: what to do after the Shun Hing Group data breach

Hong Kong's Privacy Commissioner says the Shun Hing Group data breach may involve personal data of over 921,000 people, including about 920,000 customers' names, addresses, phone numbers and emails. What affected customers should do.

Published 2026-09-30 Updated 2026-09-30 Last verified 2026-09-30 11 min read

For: customers in Hong Kong who bought appliances from, registered a warranty with, or booked installation or repairs through Shun Hing Group's businesses, or who were PanaClub members; and staff, service and supplier personnel who worked with the group. This article is based on the Office of the Privacy Commissioner for Personal Data (PCPD)'s public response and Shun Hing Group's official notice. It does not cover how the attack was carried out.

What customers should do now

1

Check whether you're affected only through official channels

Shun Hing Group says that anyone who wants to check whether their information was affected can send their name, telephone number and email address to the dedicated incident email address in its notice. Copy that address from the notice on Shun Hing Group's official website yourself; don't reply to unsolicited messages "on behalf of Shun Hing" or click their links. You can also call the PCPD on 2827 2827.

2

Treat every 'reset your PanaClub password' message as suspicious

Shun Hing Group says the PanaClub system has been suspended and that, because it is not in operation, members don't need to reset their login credentials or take any action about account access. So any email or text right now asking you to "reset your PanaClub password" or "verify your member account" contradicts the official notice. For how to recognise these, see what is phishing?.

3

For 'home repair' or 'warranty expiring' calls, hang up and call back yourself

Names, addresses and phone numbers are exactly what someone needs to pose as a repair appointment, installation follow-up or extended-warranty offer. When you get such a call or text, hang up and call back on a number you find yourself, such as the customer service hotline on your warranty card or the official website. Don't pay, log in or give details through a number or link the caller provides.

4

Follow the PCPD's advice: passwords, multi-factor authentication, login history

The PCPD advises potentially affected people to consider changing online account passwords and enabling multi-factor authentication where available, and to watch personal email and accounts for unusual logins. If you used your PanaClub password on other sites, change it there first. A password manager keeps passwords unique; for choosing a second factor, see choosing multi-factor authentication.

5

Review your bank statements

The PCPD advises reviewing bank statements for any unauthorised transactions. This matters most for the staff, service and supplier personnel whose identity document numbers and bank account numbers may have leaked, since those details can be used to pose as a bank or an employer. If you see something suspicious, call your bank on the number on your card or statement.

6

Check suspicious numbers with Scameter or 18222

The Hong Kong Police's CyberDefender site offers Scameter, which rates the scam risk of phone numbers, email addresses and websites, and the police Anti-Deception Coordination Centre runs the Anti-Scam Helpline 18222. Note that "no record" doesn't mean safe; calling back on a number you looked up is still the most reliable check.

7

Want to know what a company holds about you? Make a data access request

Under Hong Kong's Personal Data (Privacy) Ordinance, you can make a data access request to find out what personal data an organisation holds about you. According to the PCPD, you should use its prescribed data access request form, and the organisation must comply, or give reasons for refusing, within 40 days. For complaints about how your data was handled, contact the PCPD (complaints@pcpd.org.hk, 2827 2827).

Name + address + phone (customers)

→ Fake "repair appointment", "warranty expiring" or "home inspection" calls

Check: hang up, call a number you look up

Email + membership

→ "Reset your PanaClub password" or "verify your account" phishing

Check: system suspended, no reset needed

ID doc no. + bank account (staff etc.)

→ Posing as a bank or employer, identity misuse

Check: review statements, call your bank

Shun Hing: no evidence at this time that the data has been misused

Which scam each type of leaked data makes more believable, and how to check each one (this site's summary based on the PCPD's and Shun Hing Group's statements).

What happened (per the PCPD and Shun Hing Group)

The following comes from the PCPD's 2 July 2026 response to a media enquiry and Shun Hing Group's 9 July 2026 notice.

  1. 23 March 2026

    The PCPD receives a data breach notification from Shun Hing Group and opens an investigation under its established mechanism.
  2. 2 July

    Responding to a media enquiry, the PCPD cites the organisation's latest information: the personal data of more than 921,000 people may have been leaked, and that of about 1,050,000 people may have been maliciously encrypted. The PCPD says its investigation is ongoing.
  3. 9 July

    Shun Hing Group publishes a latest update: potentially involved data includes names, phone numbers, email addresses and billing or mailing addresses, with no evidence at this time of misuse; the PanaClub system has been suspended; the group is collaborating fully with law enforcement and has upgraded its cybersecurity defences.
921,000+
People whose data may have been leaked (PCPD, citing the organisation)
~920,000
Customers: names/titles, addresses, phone numbers, emails
~1,000
Staff and service/product/supplier personnel: also ID document numbers, bank accounts, salaries
~1,050,000
People whose data may have been maliciously encrypted (incl. ~1,045,000 customers)
What was involved and what wasn't (per the PCPD and Shun Hing Group)
Customers (~920,000)
Names/titles, addresses, phone numbers, email addresses (Shun Hing's notice also mentions billing or mailing addresses)
Staff, service/product/supplier personnel (~1,000)
Names/titles, addresses, phone numbers, email addresses, identity document numbers, bank account numbers, salaries, etc.
Malicious encryption
About 1,050,000 people, of whom about 1,045,000 are customers (PCPD, citing the organisation's latest information)
Misuse
Shun Hing says there is no evidence at this time that the data has been misused
PanaClub
System suspended; members don't need to reset login credentials
Investigation
Opened by the PCPD under its established mechanism; ongoing as of 2 July
Enquiries
PCPD: 2827 2827 · communications@pcpd.org.hk (enquiries) · complaints@pcpd.org.hk (complaints)

How to read it: this is the distributor's incident, not the brand manufacturer's

According to its website, Shun Hing Group has been the agent for a major Japanese home-appliance brand in Hong Kong and Macau since 1953, and provides installation and after-sales services through its service centres. The incident described here is the one the PCPD and Shun Hing Group have disclosed about Shun Hing Group; neither says any brand manufacturer's systems were affected. If a message claims to be from a "brand head office" about this incident, verify it the same way: on a number you look up yourself.

Why an old warranty registration becomes today's risk

When we buy an air conditioner, a fridge or a washing machine, we hand our name, address and phone number to a distributor or service centre for delivery, installation, warranty registration or later repairs. Unlike a password, this data doesn't expire and can't be reset: the address from before you moved, the phone number you registered years ago, may all still sit in the system. The customer data the PCPD lists here (names, addresses, phone numbers, emails) is exactly this kind of after-sales record.

Suspicious 'after-sales' contact

  • Opens by reciting your name, address and the appliance you bought
  • Says your "warranty is about to expire" and wants payment through a link
  • Asks you to "reset your PanaClub password" or "verify your account"
  • Offers a last-minute "home inspection" and pushes you to decide
  • Asks for your ID number or bank details "to verify you"

Safer habits

  • Hang up and call the number on your warranty card or the official website
  • Renew or pay only through official channels you open yourself
  • Remember: PanaClub is suspended, no password reset needed
  • Confirm home visits and the technician through the official hotline
  • Never give ID or bank details on an incoming call

The lesson isn't "learn to spot scammers". It's changing how you judge whether contact is genuine. Before, someone knowing your address and what appliance you bought was a reasonable sign it was real after-sales service. After this breach, that sign means nothing. Never decide whether a call is trustworthy while you are still on that call.

This site's view: keep an 'official contacts card' for your appliances

Write down the brand, model, purchase date and official customer service hotline for your main appliances, on a card or in a phone note. When someone calls to say "your air conditioner's warranty is expiring", you already have a number to call back, and don't need anything the caller gives you. It's also worth making a data access request to the organisations that hold your details, to learn what they keep and for how long. For organisations holding large customer databases, the lesson is to keep only what after-sales service actually needs, and delete the rest on a schedule; see the minimum security baseline for organizations.

For suspicious texts and links on your phone, see smartphone security basics. For other breaches this year where leaked contact details made fake messages more convincing, see the TVING breach in South Korea and the list of 2026 breaches.

Sources (public record)

The facts in this article are based on the public sources below. Attacker claims and unpublished figures are not used.

  • PCPD, "公署回應有關信興集團資料外洩事故" (response to media enquiry on the Shun Hing Group data breach, 2 July 2026, Chinese only) — pcpd.org.hk
  • Shun Hing Group, "Latest update on Shun Hing Group cybersecurity incident" (9 July 2026) — shunhinggroup.com
  • Shun Hing Group, official website (group profile) — shunhinggroup.com
  • PCPD, "Data Access Request" Q&A leaflet — pcpd.org.hk
  • Hong Kong Police Force, CyberDefender, Scameter — cyberdefender.hk
  • Hong Kong Police Force, Anti-Deception Coordination Centre (Anti-Scam Helpline 18222) — adcc.gov.hk

Update history

2026-09-30: First version, based on the PCPD's 2 July 2026 response to a media enquiry and Shun Hing Group's 9 July 2026 notice (as checked on 30 September 2026).

FAQ

QWhat data was involved in the Shun Hing Group breach?
A

According to the PCPD's 2 July 2026 response, based on the latest information provided by the organisation, the personal data of more than 921,000 people may have been leaked. This may include about 920,000 customers' names/titles, addresses, phone numbers and email addresses, and about 1,000 staff and service/product/supplier personnel's names/titles, addresses, phone numbers, email addresses, identity document numbers, bank account numbers and salaries. Shun Hing Group's 9 July notice says potentially involved data includes names, phone numbers, email addresses and billing or mailing addresses.

QWhat does 'maliciously encrypted' mean here?
A

The PCPD said that, according to the organisation's latest information, the personal data of about 1,050,000 people may have been maliciously encrypted, including about 1,045,000 customers. That means the data was encrypted without authorisation so the organisation could not use it normally; it is a separate figure from the number of people whose data may have been leaked. This article uses only the PCPD's figures, not claims by the attackers.

QWere customers' ID numbers or bank account numbers leaked?
A

In the PCPD's statement, identity document numbers, bank account numbers and salaries relate to about 1,000 staff and service/product/supplier personnel. For the roughly 920,000 customers, the PCPD lists names/titles, addresses, phone numbers and email addresses. To check your own case, use the dedicated email address in Shun Hing Group's notice.

QDo I need to reset my PanaClub password?
A

Shun Hing Group says the PanaClub system has been suspended and, because it is not in operation, members do not need to reset their PanaClub login credentials or take any further action about account access. So a link asking you to 'reset your PanaClub password' or 'verify your member account' should be treated as suspicious. If you used the same password on other sites, the PCPD's advice to consider changing online account passwords and enabling multi-factor authentication still applies there.

QHow can I find out whether my data was affected?
A

Shun Hing Group says anyone who wants to check can send their name, telephone number and email address to the dedicated incident email address listed in its notice. Copy that address from the notice on Shun Hing Group's official website yourself; don't reply to unsolicited messages claiming to act for Shun Hing. You can also contact the PCPD on 2827 2827.

QHow can I check a suspicious call or text in Hong Kong?
A

The PCPD urges vigilance with calls, texts or emails of unknown or suspicious origin, and not to open attachments or links or disclose personal data. The Hong Kong Police's CyberDefender site offers Scameter to check the scam risk of phone numbers, emails and websites, and the police Anti-Deception Coordination Centre runs the Anti-Scam Helpline 18222.