October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

SHEIN Owner Agreed to Pay $1.9 Million Over 2018 Data Breach

New York said Zoetop failed to notify millions of SHEIN account holders after a 2018 breach that also affected ROMWE. The company agreed to pay $1.9 million and improve security.
From TheFinanceBase Team5 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Zoetop Business Company Ltd., which the New York Attorney General identified as the owner and operator of SHEIN and ROMWE, agreed to pay New York $1.9 million in penalties and costs in October 2022. The state said a June 2018 cyberattack compromised 39 million SHEIN accounts and more than 7 million ROMWE accounts, and that Zoetop notified only a fraction of affected SHEIN account holders.

The 39 million figure counts accounts, not a confirmed number of unique people. The settlement concerned both the attack and Zoetop’s response; it is not an announcement of a new 2026 breach. New York Attorney General’s October 12, 2022 announcement

What happened in the 2018 SHEIN and ROMWE breach?

In June 2018, attackers targeted Zoetop’s systems. According to the New York Attorney General’s account, Zoetop did not first discover the intrusion itself: its payment processor alerted it after payment networks and a card issuer reported signs that the company’s systems had been infiltrated. A forensic investigation then found that attackers had accessed Zoetop’s internal network.

The attackers altered code involved in processing customer transactions in an attempt to intercept and extract payment-card information. Investigators determined that account information for 39 million SHEIN accounts had been taken. More than two years later, Zoetop found ROMWE credentials circulating on the dark web and concluded that more than 7 million ROMWE accounts had likely been compromised in the same 2018 attack. New York announced its settlement with Zoetop on October 12, 2022. New York Attorney General

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How many accounts were affected—and how many users were notified?

The state’s figures distinguish the accounts compromised from the customers it said Zoetop failed to notify. They do not establish how many distinct people were affected.

Measure New York Attorney General’s figure
SHEIN accounts compromised worldwide 39 million accounts
ROMWE accounts compromised worldwide More than 7 million accounts
New York residents affected across both brands More than 800,000 residents
New York SHEIN accounts among those affected More than 375,000 accounts
SHEIN account holders worldwide not notified More than 32.5 million
New York SHEIN account holders not notified 255,294

The figures are from the state’s settlement announcement. “39 million users” is common shorthand, but the official figure is 39 million accounts; it is not a verified count of unique individuals. New York said Zoetop notified only a fraction of affected SHEIN users and failed to alert more than 32.5 million SHEIN account holders worldwide.

What information was exposed?

The New York Attorney General identified names, email addresses and hashed account passwords among the compromised information. “Hashed” does not mean the credentials were necessarily safe: the state said the password-hashing approach in use until August 2018 was insufficient against attacks.

The investigation also found card-related exposure. Zoetop had stored some payment-card information in a plain-text debug log, and attackers changed transaction-processing code in an effort to intercept and exfiltrate card data. The state’s account does not establish that complete payment-card information was taken from every affected account. New York Attorney General

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why did New York criticize Zoetop’s security and response?

The settlement announcement described failures both before the attack and after it was discovered. The Attorney General said Zoetop:

  • Used weak password hashing until August 2018 and stored some card information in plain-text debug logs.
  • Did not regularly conduct external vulnerability scans and did not adequately monitor or review audit logs.
  • Lacked a comprehensive written incident-response plan.
  • Failed to reset passwords or otherwise protect many compromised accounts.
  • Notified only a fraction of affected SHEIN account holders and made public statements that understated the breach’s scale.

Notification matters because it gives customers a chance to change exposed or reused credentials, protect their email and financial accounts, and watch for fraud. New York’s criticism also went beyond communication: it said Zoetop did not take adequate steps to protect many affected accounts.

What did Zoetop say, and what did the Attorney General dispute?

New York said Zoetop reported that 6.42 million consumers were affected, although the state’s investigation identified 39 million compromised SHEIN accounts. The Attorney General also said Zoetop claimed it was notifying all affected customers when it had notified only a fraction.

The state further disputed Zoetop’s statement that it had seen no evidence customer credit-card information was taken from its systems. Investigators found evidence of altered transaction code and card information being exfiltrated. These are the Attorney General’s findings as described in its announcement; they should not be read as a claim that every affected account had card data stolen.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What did the $1.9 million settlement require?

Zoetop agreed to pay New York $1.9 million in penalties and costs. The agreement also required the company to maintain an information-security program that included:

  • Robust password hashing.
  • Network monitoring for suspicious activity and vulnerability scanning.
  • Incident-response policies requiring timely investigation and consumer notice.
  • Prompt password resets after relevant incidents.

This was a settlement with the New York Attorney General, not a criminal conviction or simply a court-imposed fine. The payment and required improvements are described in the state’s settlement announcement.

What should former SHEIN or ROMWE customers do now?

Because the attack dates to 2018, the practical priority is to remove any lingering password reuse and check for signs of financial or identity fraud. A password change today cannot undo the historical exposure, but it can stop an old credential from unlocking an account now.

  1. Replace reused passwords. Change any password still used on SHEIN or ROMWE, then change it anywhere else you reused or slightly modified it—especially email, banking, payment and social accounts. Use a unique password for each account.
  2. Secure your email and financial accounts. Turn on multifactor authentication wherever available, prioritizing email and financial services. Email access can make it easier for an attacker to reset other passwords.
  3. Review payment activity. Check bank and card statements for unfamiliar transactions. Contact the card issuer promptly about suspicious charges or a card you believe was exposed; follow its advice on replacing the card.
  4. Watch for targeted phishing. Be cautious about messages mentioning SHEIN or ROMWE orders, refunds, coupons, account verification or password resets. Do not follow a link in an unexpected message to sign in; go to the service directly instead.
  5. Check your credit if identity theft is a concern. U.S. consumers can review reports at AnnualCreditReport.com. If you see signs of identity theft or believe your personal information puts you at risk, consider freezing your credit with all three major bureaus: Equifax, Experian and TransUnion. A freeze restricts access to your credit file for new-credit applications; it does not replace monitoring card or bank accounts.
  6. Use trusted breach-checking resources carefully. A reputable breach-notification service may help identify whether an old email address appears in known incidents. Never enter a current password into a site you do not trust.
  7. Close unused shopping accounts if practical. Remove stored payment details first where the service allows, then delete accounts you no longer need.

If you suspect identity theft, the Federal Trade Commission’s IdentityTheft.gov offers free recovery guidance. Paid monitoring is optional; it does not substitute for changing reused passwords, contacting a card issuer about suspicious activity, or placing a credit freeze when appropriate.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What this case does—and does not—establish

The New York settlement establishes that Zoetop agreed to pay penalties and costs and to make specified security improvements after the state’s investigation into the 2018 incident and response. It does not establish a count of 39 million unique people, that every affected account lost complete card data, or that SHEIN suffered a new breach in 2026. The dates matter: the attack was in June 2018; the state announced the agreement on October 12, 2022. New York Attorney General

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.