The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →The SHEIN breach happened in June 2018—not recently. In October 2022, New York’s Attorney General said 39 million SHEIN account credentials were stolen, far more than the 6.42 million consumers Zoetop had publicly said were affected. The investigation also found that many affected users were not notified. The findings are the Attorney General’s account of the investigation and settlement, not an individual check of any reader’s account.
What happened in the SHEIN breach?
New York’s Attorney General reported that Zoetop, then the operator of SHEIN and ROMWE, was targeted in a cyberattack in June 2018. According to the state’s investigation, attackers entered the company’s internal network, accessed customer information and altered transaction-processing code in an effort to intercept and take payment-card information.
The investigation found that SHEIN customer information exposed included names, email addresses and hashed account passwords. The Attorney General said the password-hashing method used at the time was insufficient. A forensic firm could not determine whether payment-card information was successfully exfiltrated, so the official findings do not establish that card numbers were stolen.
How many accounts were affected?
| Figure | What it refers to |
|---|---|
| 39 million | SHEIN account credentials stolen, according to the New York State Office of the Attorney General in 2022. |
| 7 million | ROMWE accounts involved in the incident, according to the New York State Office of the Attorney General in 2022. |
| 6.42 million | The number of consumers Zoetop said were affected; the Attorney General said that figure understated the SHEIN impact. |
| More than 32.5 million | SHEIN users whom the Attorney General said Zoetop did not alert that their credentials had been stolen. |
The figures and notification findings are from the New York Attorney General’s October 12, 2022 announcement. They describe the incident in aggregate; they do not show whether a particular customer was affected or received a notice.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
Were credit-card details stolen?
The Attorney General’s findings say attackers changed transaction-processing code in an attempt to intercept and exfiltrate card information. But the forensic firm could not determine whether payment-card data was successfully taken. It would therefore be inaccurate to say the investigation confirmed that card details were stolen.
The state said New York secured $1.9 million in penalties and costs in 2022. The assurance records SHEIN Distribution Corporation and Zoetop Business Company, Limited among the parties and describes agreed relief; it does not establish that Zoetop is SHEIN’s current operating entity. See the executed assurance for the formal record.
What should you do if you had a SHEIN account?
The historical findings do not establish that your account remains compromised, whether you were individually notified, or whether you were among the affected users. You can still reduce the risk from password reuse:
- Change any reused password. If the password you used for SHEIN appears on another account, replace it there with a different, unique password. Attackers may try credentials stolen from one service on other services, a practice known as credential stuffing.
- Use a unique password for every account. A password manager can optionally generate and store distinct passwords. The Attorney General’s guidance does not endorse a particular product.
- Pay attention to account notices. The Attorney General says businesses responding to an incident should secure affected accounts, including by resetting passwords or notifying customers that accounts are at risk. If you receive a relevant notice, follow its instructions through the company’s official site or app.
The New York Attorney General’s consumer guidance on exposed information explains credential stuffing and steps businesses should take after an incident.
Recommended Free Tools
Why the breach was reported as “over 6 million”
The headline figure reflects Zoetop’s understated public account, not the later count reported by New York’s Attorney General. The state said 39 million SHEIN credentials were stolen and that Zoetop falsely represented that only 6.42 million consumers were affected while claiming it was notifying all affected users. According to the Attorney General, more than 32.5 million SHEIN users were not alerted that their credentials had been stolen.
In announcing the 2022 settlement, Attorney General Letitia James said: “SHEIN and ROMWE’s weak digital security measures made it easy for hackers to shoplift consumers’ personal data.”
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




