Sagawa Express leaks ~70,000 users' data: delivery emails showed other people's names, caused by a config error
Japanese delivery giant Sagawa Express says up to about 70,000 users' personal data may have leaked through its "Smart Club" service. Delivery notification emails showed another person's name, email address and parcel tracking number. The cause was not a cyberattack but a configuration mistake made during recovery work. Here is what leaked, what did not, and how to avoid the Sagawa-impersonating scam emails that follow.
Table of contents
Japanese delivery giant Sagawa Express says up to about 70,000 users' personal data may have leaked through its "Smart Club" service. Delivery notification emails showed another person's name, email address and parcel tracking number. The cause was not a cyberattack but a configuration mistake made during recovery work. Here is what leaked, what did not, and how to avoid the Sagawa-impersonating scam emails that follow.
If you use Sagawa Express's "Smart Club" service and saw a stranger's name in a delivery notification email, or worry that your own details were exposed to someone else, here is the bottom line first. On July 18, 2026, Sagawa Express officially announced that some delivery notification emails had shown another user's name, email address and other details by mistake. The data of about 70,000 people may have been affected.
The information that may have leaked is limited to three items: name, email address, and the parcel "tracking number" (γεγεγιγηΆNo.). Home addresses, phone numbers and credit card details were not involved. The cause was not an outside attack but a configuration mistake in the notification email settings, made while fixing a separate system glitch. Sagawa says the problem has already been corrected and the service, including email notifications, is working normally again. Affected users will receive an apology and guidance from Sagawa by email in sequence.
Most reports simply repeat the headline figures β "about 70,000 affected," "caused by a settings error." This article, written for people who actually use Smart Club, first sorts out what you should do, then explains from an engineer's point of view: what actually got crossed inside the system so that a stranger's name appeared, why a leaked tracking number matters, and why the very work meant to fix a glitch created a new leak. Confirmed facts and still-unpublished details are kept separate.
This was not a theft by an intruder. Instead, the work of fixing Sagawa's own system ended up mixing and sending out other people's information β a self-inflicted accident. That is exactly why the fix points in a different direction from defending against outside attacks. Let's walk through what happened.
What happened, on a timeline
First, here are the facts in order, based on Sagawa's announcement and news reports. The key point is the sequence: the "recovery work" meant to fix a glitch is what triggered a new defect β other people's information showing up.
β swipe to move
According to Sagawa, the problem occurred on the evening of July 15 and was fixed from July 16 onward. The company disclosed it about three days later, on July 18. ITmedia NEWS and the Nikkei both reported that the emails displayed other people's names and that the cause was a settings error. The Asahi Shimbun described it as "mis-sent notification emails." Rather than the wrong address being used, a single email contained another person's information β which is what makes this incident confusing at first glance.
What leaked, and what did not
The most important thing to judge your own risk is "what could have gone out." Based on Sagawa's announcement, here is what was and was not affected.
| Category | Details |
|---|---|
| May have leaked | Name / email address / parcel tracking number (γεγεγιγηΆNo.) |
| Not included | Home address / phone number / credit card details / bank account |
| Scale | Up to about 70,000 people (potentially affected) |
That addresses and card data were not involved is a small mercy. But the tracking number deserves attention. It is a 12-digit code assigned to each parcel, and entering it into Sagawa's parcel tracking service lets anyone check that parcel's delivery status. So when a name, an email address and this number line up, the fact that "a parcel is on its way to this person right now" becomes visible to a stranger. As we'll see, that is a bad match for fake "missed delivery" scams impersonating Sagawa.
What actually got crossed to show a stranger's name
Sagawa's explanation is short: "an error occurred in the delivery notification email settings." But once you know how these emails are built, the meaning becomes clearer. Here is what has to go wrong for one person's data to end up in another person's email.
Notification emails combine "recipient" and "content" after the fact
Mass emails like delivery notifications are not written one by one. The system prepares "who to send to (the recipient list)" and "what to write (the content to merge in)" separately, then a machine combines them one record at a time β the same idea as mail-merging an address list with a letter template. If this pairing between recipient and content slips by even one record, person A's email gets person B's content.
The "other person's name and email address showing up" is most naturally understood as exactly this pairing breaking. The recipient order and content order slip by one; a shared temporary work area (a cache) still holds the previous person's data; or a merge variable points at the wrong person's record. Sagawa has not published the internal mechanics, so this cannot be stated as fact β but all of these come down to one thing: "the map between recipient and content was broken." This paragraph is inference from how such emails are generally built, not a confirmed detail.
Why "recovery work" was the trigger
What must not be missed is that this settings error arose during "recovery work" to fix a glitch. A separate system defect existed first; the work to fix it left the notification email settings in a wrong state. The repair opened a hole somewhere else.
This is a familiar shape of accident. Emergency fixes made mid-incident, under time pressure, tend to skip the reviews and tests that a normal release would always go through. Security outlet Security Measures Lab likewise notes that emergency recovery work tends to simplify the usual review and testing, raising the risk of misconfiguration, and stresses change management and multi-person double-checking. Whether the recipient-to-content pairing was correct is exactly the kind of slip you could have caught by sending a handful of test emails against near-production data and simply reading them.
What the damage looks like if this is abused
This was not a theft by an outside attacker. But for scam groups that impersonate delivery companies, the combination of name, email address and tracking number is convenient raw material. If this data were abused somehow, here is the damage to expect.
Their specialty is sending convincing fake "missed delivery" or "please rebook delivery" messages. An email or SMS that greets you by name and cites a real tracking number looks genuine β especially to someone actually expecting a parcel. The goal is to get you to open a fake link and enter your ID, password or card details on a fake site dressed up as Sagawa. A scam you would normally spot slips through when it lands right as you're waiting for a package and carries your real name and a real number.
The harm runs in two directions. Users waiting for a parcel risk being lured to a fake redelivery site and having their accounts or card data stolen. Sagawa, for its part, has unintentionally handed scammers material for impersonating its own brand, denting trust. That is why the "what to do now" steps below matter even in this case, where addresses and cards did not leak.
What Smart Club users should do now
Here is what Smart Club members, and anyone expecting a Sagawa delivery, should do now. No special setting change is needed, but for a while it pays to be wary of anything claiming to be from Sagawa.
- βΈWait for Sagawa's apology email: potentially affected users will receive an apology and guidance in sequence. Check the official contact first.
- βΈDon't tap links in "missed delivery" or "redelivery" emails/SMS: to check a parcel, open the official Sagawa site or app yourself and enter the number there β not the link in the message.
- βΈIf an email carried someone else's name, don't repost it: if another person's name or email address was visible, posting it to social media makes you the one spreading their data.
- βΈStop reusing your Smart Club password: your password did not leak here, but since your email address was exposed to a third party, reuse becomes a bigger target. Move to unique passwords.
- βΈTake questions to the official contact: confirm the details and whether you are affected through Sagawa's notice and official inquiry channels.
Fake emails and SMS impersonating delivery firms have been circulating widely regardless of this incident. The tactics and how to spot them overlap with the thinking in our earlier piece on what users should do after a large email-service breach. Even when the name and number are real, treat anything that pushes you to enter information on a linked page as suspect β that single rule blocks most of the harm.
How to read a leak that wasn't an attack
From here, the writer's view based on the facts. The point worth holding onto is that personal data can leak even without any outside attack. "Leak" tends to conjure hacking and unauthorized access, but in reality a company's own operational mistakes and misconfigurations are a frequent cause.
Structurally, this closely resembles the case we covered recently in which Kitakyushu residents received other people's insurance payment slips. There too, a new system's settings and a machine's handling slipped, delivering someone else's information into the wrong hands. By contrast, the Awa Bank leak from a test environment, where an outside attacker broke in, differs completely in the path, in who received the data, and in the danger level. Even the same word "leak" needs to be split into "by attack" and "by our own mistake."
When many people's personal data becomes visible to outsiders like this, companies are, in principle, expected to report to Japan's Personal Information Protection Commission and notify the individuals (when certain conditions are met). Whether or not it was an attack, a leak is treated as a leak. Sagawa disclosing the facts fairly quickly after the incident looks like a response mindful of that framework. As another domestic-service failure, a single company's trouble can ripple widely to users and partners β as seen when a supply chain seized up in the Nichirei system outage.
In the sites this writer has worked on, accidents tend to happen during emergency fixes made mid-incident. Compared with calm, planned releases, work done under "we have to fix this right now" is where checks get skipped. The lesson here comes down to a plain but effective habit: after fixing a glitch, always verify that the fix didn't break something else.
FAQ
Was my personal data leaked?
Up to about 70,000 people's data may have been affected, and potentially affected users will receive an apology and guidance from Sagawa by email in sequence. What may have leaked is name, email address and the parcel tracking number (γεγεγιγηΆNo.); home address, phone number and credit card details were not involved. Check for the official notice from Sagawa first.
Was it caused by a cyberattack or unauthorized access?
No. Sagawa says it confirmed this was not unauthorized access or a cyberattack by a third party. The cause was a configuration error in the delivery notification email settings, introduced while carrying out recovery work on a separate system glitch. The issue has already been fixed and the service is working normally.
Why is a leaked tracking number dangerous?
The tracking number lets anyone check a parcel's delivery status. Paired with a name and email address, it makes fake "missed delivery" or "redelivery" emails and SMS impersonating Sagawa more convincing. Even when the name and a real number appear, don't tap links in the message β open the official site or app yourself and check there.
What should I do right now?
Check for Sagawa's apology email, and don't tap links in any "missed delivery" or "redelivery" messages claiming to be from Sagawa. If an email showed another person's name, don't repost it on social media. If you reuse your Smart Club password on other services, change to unique passwords now to stay safe.
Sources
- βΈSagawa Express - Notice on the risk of personal data leakage in Smart Club (official notice, Japanese)
- βΈITmedia NEWS - Sagawa Express: ~70,000 people's data possibly leaked; "Smart Club" emails showed other people's names (Jul 18, 2026)
- βΈNikkei - Sagawa Express leaks personal data of ~70,000 due to a system settings error (Jul 18, 2026)
- βΈChunichi Shimbun - Sagawa Express leaks data of 70,000; names and emails, due to a settings error
- βΈSecurity Measures Lab - Sagawa "Smart Club": ~70,000 personal records possibly exposed by a system glitch
- βΈJapanSecuritySummit Update - Sagawa "Smart Club": risk of ~70,000 personal records leaking
- βΈPersonal Information Protection Commission, Japan

Makoto Horikawa
Backend Engineer / AWS / Django