October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

SHEIN Data Breach: What Happened to 39 Million Accounts

New York’s Attorney General said 39 million SHEIN credentials were stolen in a June 2018 breach. Here’s what the findings establish—and what steps can help protect accounts using a reused password.
From TheFinanceBase Team3 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The SHEIN breach happened in June 2018—not recently. In October 2022, New York’s Attorney General said 39 million SHEIN account credentials were stolen, far more than the 6.42 million consumers Zoetop had publicly said were affected. The investigation also found that many affected users were not notified. The findings are the Attorney General’s account of the investigation and settlement, not an individual check of any reader’s account.

What happened in the SHEIN breach?

New York’s Attorney General reported that Zoetop, then the operator of SHEIN and ROMWE, was targeted in a cyberattack in June 2018. According to the state’s investigation, attackers entered the company’s internal network, accessed customer information and altered transaction-processing code in an effort to intercept and take payment-card information.

The investigation found that SHEIN customer information exposed included names, email addresses and hashed account passwords. The Attorney General said the password-hashing method used at the time was insufficient. A forensic firm could not determine whether payment-card information was successfully exfiltrated, so the official findings do not establish that card numbers were stolen.

How many accounts were affected?

Figure What it refers to
39 million SHEIN account credentials stolen, according to the New York State Office of the Attorney General in 2022.
7 million ROMWE accounts involved in the incident, according to the New York State Office of the Attorney General in 2022.
6.42 million The number of consumers Zoetop said were affected; the Attorney General said that figure understated the SHEIN impact.
More than 32.5 million SHEIN users whom the Attorney General said Zoetop did not alert that their credentials had been stolen.

The figures and notification findings are from the New York Attorney General’s October 12, 2022 announcement. They describe the incident in aggregate; they do not show whether a particular customer was affected or received a notice.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Were credit-card details stolen?

The Attorney General’s findings say attackers changed transaction-processing code in an attempt to intercept and exfiltrate card information. But the forensic firm could not determine whether payment-card data was successfully taken. It would therefore be inaccurate to say the investigation confirmed that card details were stolen.

The state said New York secured $1.9 million in penalties and costs in 2022. The assurance records SHEIN Distribution Corporation and Zoetop Business Company, Limited among the parties and describes agreed relief; it does not establish that Zoetop is SHEIN’s current operating entity. See the executed assurance for the formal record.

What should you do if you had a SHEIN account?

The historical findings do not establish that your account remains compromised, whether you were individually notified, or whether you were among the affected users. You can still reduce the risk from password reuse:

  1. Change any reused password. If the password you used for SHEIN appears on another account, replace it there with a different, unique password. Attackers may try credentials stolen from one service on other services, a practice known as credential stuffing.
  2. Use a unique password for every account. A password manager can optionally generate and store distinct passwords. The Attorney General’s guidance does not endorse a particular product.
  3. Pay attention to account notices. The Attorney General says businesses responding to an incident should secure affected accounts, including by resetting passwords or notifying customers that accounts are at risk. If you receive a relevant notice, follow its instructions through the company’s official site or app.

The New York Attorney General’s consumer guidance on exposed information explains credential stuffing and steps businesses should take after an incident.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why the breach was reported as “over 6 million”

The headline figure reflects Zoetop’s understated public account, not the later count reported by New York’s Attorney General. The state said 39 million SHEIN credentials were stolen and that Zoetop falsely represented that only 6.42 million consumers were affected while claiming it was notifying all affected users. According to the Attorney General, more than 32.5 million SHEIN users were not alerted that their credentials had been stolen.

In announcing the 2022 settlement, Attorney General Letitia James said: “SHEIN and ROMWE’s weak digital security measures made it easy for hackers to shoplift consumers’ personal data.”

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.