Skip to content
Data breachResolved

SHEIN data breach (2018)

In June 2018, fast-fashion retailer SHEIN suffered a breach of its payment systems exposing about 39 million account credentials. In 2022, New York fined parent company Zoetop $1.9 million for understating the breach and failing to notify most victims.

Victim
SHEIN
Loss
$1.9M
records
39.1M
users
39.1M

In June 2018, the fast-fashion e-commerce giant SHEIN β€” then operated by Hong Kong-based parent company Zoetop Business Co., which also owns the Romwe brand β€” suffered a data breach affecting roughly 39 million customer accounts. Four years later, the New York Attorney General fined Zoetop $1.9 million for downplaying the breach and failing to notify most of the affected users.

What happened

A malicious third party gained unauthorised access to SHEIN's payment systems beginning around June 2018. SHEIN did not discover the intrusion until August 2018 β€” roughly two months later β€” and disclosed it publicly about a month after that. The stolen data comprised email addresses and MD5-hashed passwords for 39,086,762 unique accounts; the dataset was subsequently added to Have I Been Pwned in October 2018.

The breach gained renewed attention in October 2022 when the New York Attorney General published the findings of its investigation, concluding that Zoetop had seriously mishandled both the incident and its public response.

Impact

  • Around 39 million account credentials were stolen globally, including those of more than 375,000 New York residents.
  • Passwords were protected only by unsalted MD5 hashing, making many trivially crackable.
  • The NY AG found that Zoetop falsely claimed only 6.42 million individuals were affected and that it was notifying all impacted users β€” when in fact it had contacted only a fraction of the 39 million.
  • Investigators also found that Zoetop failed to require affected users to reset passwords and misrepresented the scope and handling of the breach. The result was a $1.9 million penalty in October 2022.

Why it matters

The SHEIN case is less about the technical sophistication of the attack than about breach-response failure and regulatory accountability. New York penalised Zoetop not primarily for being breached, but for understating its scale, misleading consumers, and failing to notify the vast majority of victims β€” duties that data-breach notification laws exist to enforce.

It is also a reminder that weak password hashing (unsalted MD5) compounds harm long after the initial theft, and that fast-growing consumer platforms operating across many jurisdictions face mounting obligations to disclose breaches promptly and accurately. The fine became a frequently cited example in cybersecurity-awareness discussions of how regulators treat opacity around data breaches.

Financial impact

Reported costs in USD

Total reported loss
1.9M
USD Β· $1,900,000
  • Fines & settlements$1.9M

Timeline

  1. A malicious third party gains unauthorised access to SHEIN's payment and account systems.

  2. SHEIN discovers the breach roughly two months after it began.

  3. SHEIN publicly discloses the incident, about a month after discovery.

  4. A dataset of 39,086,762 unique email addresses with MD5 password hashes is added to Have I Been Pwned.

  5. The New York Attorney General fines parent company Zoetop $1.9 million for mishandling the breach and misleading the public.

Sources

  1. haveibeenpwned.comhttps://haveibeenpwned.com/Breach/SHEIN
  2. techcrunch.comhttps://techcrunch.com/2022/10/13/shein-zoetop-fined-1-9m-data-breach/
  3. infosecurity-magazine.comhttps://www.infosecurity-magazine.com/news/zoetop-fined-dollar19m-for-data/
  4. cshub.comhttps://www.cshub.com/attacks/news/shein-fined-us19mn-over-data-breach-affecting-39-million-customers

Related incidents

Data breachResolved

IIMJobs data breach (2018)

In December 2018, the Indian job portal IIMJobs suffered a data breach that exposed 4.1 million unique email addresses. The data also included names, phone numbers, geographic locations, dates of birth, job titles, job applications and cover letters plus passwords stored as unsalted MD5 hashes.

Victim
IIMJobs
Records
4.2M
Data breachResolved

BlankMediaGames data breach (2018)

In December 2018, the Town of Salem website produced by BlankMediaGames suffered a data breach. Reported to HIBP by DeHashed, the data contained 7.6M unique user email addresses alongside usernames, IP addresses, purchase histories and passwords stored as phpass hashes.

Victim
BlankMediaGames
Records
7.6M
Data breachResolved

OGUsers (2019 breach) data breach (2018)

In May 2019, the account hijacking and SIM swapping forum OGusers suffered a data breach. The breach exposed a database backup from December 2018 which was published on a rival hacking forum. There were 161k unique email addresses spread across 113k forum users and other tables in the database.

Victim
OGUsers (2019 breach)
Records
161.1K
Data breachResolved

Wanelo data breach (2018)

In approximately December 2018, the digital mall Wanelo suffered a data breach. The data was later placed up for sale on a dark web marketplace along with a collection of other data breaches in April 2019.

Victim
Wanelo
Records
23.2M