SF Express warns of phishing texts as Hong Kong users receive failed delivery messages

386

18th August 2026 – (Hong Kong) SF Express has urged customers to be vigilant after a surge in fraudulent messages claiming deliveries have failed or collection is required, with recipients prompted to call unknown numbers or contact couriers directly. The logistics firm said it has replaced traditional SMS notifications with its official mobile applications to reduce the risk of deception and reminded users that genuine service alerts are now pushed through the SFHK App rather than by text.

The company said recent scams include spoofed SMS and emails sent under misleading names such as “Express”, featuring headers labelled “Sf Express” and fabricated tracking references to mimic authentic updates. In coordination with the Police Force’s Anti‑Deception Coordination Centre, Sf Express has intensified public warnings as criminals continue to blast phishing content across multiple channels in an attempt to harvest personal and banking details.

Sf Express reiterated that customers should verify waybill numbers and parcel status either in the SF‑Express App or via the Hong Kong official website instead of following links embedded in unsolicited messages. The firm added that when it calls customers it will not use pre‑recorded Mandarin messages, nor will it transfer calls to any law‑enforcement or financial institution. Official texts and emails will not quote fees, request payment through hyperlinks, or ask for internet‑banking passwords or one‑time passcodes.

The company advised the public not to respond to suspicious calls, emails or texts and to safeguard personal information by avoiding unknown links, refraining from sharing credentials and never initiating transfers or remittances prompted by unsolicited contact. Parents who shop online frequently are encouraged to share these precautions with family members and carers.

Users also reported lookalike booking confirmations for theme‑park tickets and travel products, including messages purporting to be from platforms such as Klook and attractions like Hong Kong Disneyland. These emails typically claim payment failure or booking issues and entice victims to click through to phishing pages that attempt to capture card and bank data. Other prevalent tactics include impostors posing as buyers on online marketplaces and fake customer‑service agents for e‑wallets, banks and retailers who pressure targets to “cancel” non‑existent policies or settle charges, then coax them into disclosing account information, balances and personal identifiers.