Shitexpress Data Breach (2022): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The Shitexpress Data Breach (2022) (reported August 8, 2022) exposed Email addresses, IP addresses, Names and Physical addresses belonging to roughly 24K people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
In August 2022, the online novelty delivery service Shitexpress experienced a data breach that exposed personal information tied to roughly 24,000 unique email addresses. Public reporting dated 8 August 2022 indicates the incident involved records spanning invoices, gift cards, promotions and payment-related entries, along with sender and recipient details and accompanying messages. Exact technical circumstances remain limited in the public record, yet the volume and nature of the data make the event consequential for anyone who used or received services from the platform.
What is confirmed is the scale of unique email addresses involved and the categories of information that surfaced. No further official breakdown of root cause, attacker identity or full forensic timeline has been widely detailed, so the account below stays strictly within those known points while explaining the broader context in plain terms.
What happened
According to contemporaneous reporting, Shitexpress, an online faeces delivery service, suffered a data breach in August 2022. The incident exposed approximately 24,000 unique email addresses. Those addresses were linked to invoices, gift cards, promotions and PayPal records. In addition, the breach disclosed IP addresses and email addresses of senders, physical addresses of recipients, and the private messages that accompanied the deliveries.
Public detail does not extend to the precise intrusion method, the duration of unauthorised access, or whether the data appeared on a leak site under any particular claim. The reported figure of 24,000 people affected and the listed data types constitute the core Reported Facts. No dollar amounts, file counts beyond the email total, or named threat actors appear in the available summary.
How a breach like this happens
Incidents of this type commonly begin when an attacker gains initial access through commonplace weaknesses: stolen or reused credentials, unpatched software, misconfigured cloud storage, or phishing that tricks an employee or customer into revealing login details. Once inside, the intruder may move laterally, locate databases or export files containing customer records, then exfiltrate the material.
In many cases the stolen data later circulates on criminal forums or is offered for sale. Organisations that process orders, payments and personal messages routinely accumulate email addresses, shipping details, IP logs and transaction histories; a single compromised system holding those records can therefore expose a large set of individuals at once. No specific group has been attributed to the Shitexpress incident, and the precise vector used here remains undisclosed. The pattern itself, however, is familiar across retail and novelty e-commerce platforms that handle both sender and recipient information.
Shitexpress and its sector
Shitexpress operates as a novelty online service that arranges the delivery of animal faeces, typically marketed as a prank or gag gift. Businesses in this narrow sector function like other direct-to-consumer e-commerce operations: customers place orders, supply payment and shipping details, and often include personalised messages. The company therefore holds the same categories of data found at ordinary online retailers—contact information, addresses, purchase histories and communications—plus the unusual context of the product itself.
A breach at such a service is consequential because the data pairs ordinary identifiers with potentially embarrassing transaction details. Recipients may never have consented to the order, and senders may have used the service under the assumption of relative privacy. Even without sensational framing, the combination of real names, physical addresses and private messages creates clear privacy and social risks that ordinary retail breaches do not always carry to the same degree.
What data was at risk
The facts name the following categories as exposed: email addresses, IP addresses, names, physical addresses, private messages and purchases. Reporting further notes that the email addresses spanned invoices, gift cards, promotions and PayPal records, and that sender IP and email addresses, recipient physical addresses and accompanying delivery messages were included.
Organisations of this kind typically also retain order timestamps, payment-processor references and basic account metadata; whether any of those additional elements were present in the exposed set is unconfirmed. The concrete points established by the public summary are therefore limited to the types listed above and the approximate count of 24,000 unique email addresses.
The real-world impact
For affected individuals the immediate risks are practical rather than abstract. Exposed email addresses and names can be used for targeted phishing or social-engineering attempts that reference the novelty purchase. Physical addresses of recipients raise the possibility of unwanted physical mail or, in rare cases, harassment. Private messages accompanying deliveries may contain personal remarks that become awkward or damaging if circulated. IP addresses can, in combination with other data, help map approximate locations or link activity across services.
For the organisation the consequences include loss of customer trust, potential regulatory scrutiny under data-protection rules, and the operational cost of notification and remediation. Because the service inherently involves sensitive or embarrassing transactions, the reputational effect can be sharper than for a conventional retailer. No public figure for financial loss or confirmed secondary misuse has been supplied in the available facts, so those outcomes remain outside the verified record.
Were you affected?
If you placed an order with Shitexpress, received a delivery, or used an email address associated with invoices, gift cards or promotions around or before August 2022, your information may be among the exposed records. Practical first steps include:
- Changing passwords on any account that shared the same email or credentials, and enabling multi-factor authentication where available.
- Watching for phishing messages that reference novelty deliveries, PayPal, or unexpected packages.
- Reviewing bank or payment-provider statements for unfamiliar charges.
- Considering a credit or identity-monitoring service if physical addresses or full names were involved.
- Running a free exposure scan of your email address to check whether it has appeared in known breach data sets.
Public detail on this incident remains limited to the points summarised above. Staying alert to unusual contact and securing reused credentials are the most direct actions available to individuals while further official information, if any, emerges.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
RailYatri Data Breach (2022)Gemini Data Breach (2022)SevenRooms Data Breach (2022)Activision Data Breach (2022)Latest breaches
Read GalaxyWarden’s full analysis of the Shitexpress Data Breach (2022) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.