SHEIN data breach (2018)
In June 2018, fast-fashion retailer SHEIN suffered a breach of its payment systems exposing about 39 million account credentials. In 2022, New York fined parent company Zoetop $1.9 million for understating the breach and failing to notify most victims.
- Victim
- SHEIN
- Loss
- $1.9M
- records
- 39.1M
- users
- 39.1M
In June 2018, the fast-fashion e-commerce giant SHEIN β then operated by Hong Kong-based parent company Zoetop Business Co., which also owns the Romwe brand β suffered a data breach affecting roughly 39 million customer accounts. Four years later, the New York Attorney General fined Zoetop $1.9 million for downplaying the breach and failing to notify most of the affected users.
What happened
A malicious third party gained unauthorised access to SHEIN's payment systems beginning around June 2018. SHEIN did not discover the intrusion until August 2018 β roughly two months later β and disclosed it publicly about a month after that. The stolen data comprised email addresses and MD5-hashed passwords for 39,086,762 unique accounts; the dataset was subsequently added to Have I Been Pwned in October 2018.
The breach gained renewed attention in October 2022 when the New York Attorney General published the findings of its investigation, concluding that Zoetop had seriously mishandled both the incident and its public response.
Impact
- Around 39 million account credentials were stolen globally, including those of more than 375,000 New York residents.
- Passwords were protected only by unsalted MD5 hashing, making many trivially crackable.
- The NY AG found that Zoetop falsely claimed only 6.42 million individuals were affected and that it was notifying all impacted users β when in fact it had contacted only a fraction of the 39 million.
- Investigators also found that Zoetop failed to require affected users to reset passwords and misrepresented the scope and handling of the breach. The result was a $1.9 million penalty in October 2022.
Why it matters
The SHEIN case is less about the technical sophistication of the attack than about breach-response failure and regulatory accountability. New York penalised Zoetop not primarily for being breached, but for understating its scale, misleading consumers, and failing to notify the vast majority of victims β duties that data-breach notification laws exist to enforce.
It is also a reminder that weak password hashing (unsalted MD5) compounds harm long after the initial theft, and that fast-growing consumer platforms operating across many jurisdictions face mounting obligations to disclose breaches promptly and accurately. The fine became a frequently cited example in cybersecurity-awareness discussions of how regulators treat opacity around data breaches.
Financial impact
Reported costs in USD
- Fines & settlements$1.9M
Timeline
A malicious third party gains unauthorised access to SHEIN's payment and account systems.
SHEIN discovers the breach roughly two months after it began.
SHEIN publicly discloses the incident, about a month after discovery.
A dataset of 39,086,762 unique email addresses with MD5 password hashes is added to Have I Been Pwned.
The New York Attorney General fines parent company Zoetop $1.9 million for mishandling the breach and misleading the public.
Sources
- haveibeenpwned.comhttps://haveibeenpwned.com/Breach/SHEIN
- techcrunch.comhttps://techcrunch.com/2022/10/13/shein-zoetop-fined-1-9m-data-breach/
- infosecurity-magazine.comhttps://www.infosecurity-magazine.com/news/zoetop-fined-dollar19m-for-data/
- cshub.comhttps://www.cshub.com/attacks/news/shein-fined-us19mn-over-data-breach-affecting-39-million-customers