Data breach
Romwe
- Records
- 20,315,079
- Breach date
- 1 June 2018Estimated
- Added
- 1 December 2024
What was exposed
6 types of data · 1 more reported · 1 puts you at serious risk
- Email addresses20,313,459
- IP addresses19,626,982
- Passwords15,927,845
- Names6,363,326
- Phone numbers6,337,847
- Facebook profiles3,404,121
- UsernamesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In mid-2018, hackers broke into the systems of Zoetop, the Hong Kong company behind the fast-fashion retailers Shein and Romwe. According to the New York Attorney General's office, attackers exfiltrated the login credentials of nearly 7.3 million Romwe accounts, and the stolen passwords later surfaced on a dark web market in plaintext, meaning the original passwords had been cracked. The investigation team estimates the breach involved more than 20.3 million records tied to Romwe customers, with an estimated attack date of June 1, 2018. The company did not confirm the full scope of the Romwe exposure until roughly two years after the intrusion.
Breach Timeline
June 2018: Zoetop was targeted in a cyberattack, according to the New York Attorney General's investigation.
July 18, 2018: Zoetop's payment processor alerted the company that its systems appeared to have been compromised.
June 12, 2020: Zoetop discovered that Romwe customer login credentials were available on the dark web, per the Attorney General's findings.
June 18, 2020: Zoetop reset the passwords of affected Romwe accounts, at first without notifying customers.
December 30, 2020: Romwe emailed potentially affected customers with access codes for identity theft protection services, according to the company's data security FAQ.
October 2022: Zoetop agreed to pay $1.9 million to settle the New York Attorney General's investigation.
What Information Was Compromised?
Our analysis found the following data types in this breach: about 20.3 million email addresses, roughly 19.6 million IP addresses, approximately 15.9 million passwords, about 6.4 million names, roughly 6.3 million phone numbers, and approximately 3.4 million Facebook account identifiers.
Romwe's own data security FAQ said the stolen usernames and passwords could have provided access to customer account information including names, email addresses, phone numbers, or other optional details customers had stored. The New York Attorney General's investigation found the Romwe credentials were in plaintext when discovered on the dark web, having been cracked from a weak hashing method Zoetop used in 2018.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Because the exposed passwords were available in plaintext, anyone who reused the same password on other sites faces a real risk of account takeover. Stolen email and password pairs are commonly fed into automated credential stuffing attacks, which try the same combinations against banking, email, and social media logins. Names, phone numbers, and email addresses also fuel targeted phishing, in which scammers pose as a retailer or delivery service to extract payment details. The New York Attorney General noted Zoetop could not determine whether a debug log containing some full card numbers was taken, though Romwe's FAQ said the company does not store customers' full payment card information.
What Is Romwe Doing in Response?
After the 2020 discovery, Romwe forced password resets for potentially affected customers and notified them by email, according to its FAQ. The company also offered identity theft protection services through IDX and said it had taken steps to secure the platform. The New York settlement additionally required Zoetop to adopt stronger password hashing, network monitoring, vulnerability scanning, and a written incident response plan. A class action filed in 2023 alleges the company concealed the breach's impact for two years.
What Should You Do If You Were Affected?
Change your Romwe password immediately, and if you reused that password anywhere else, change it there too. Use a unique password for each account and enable two-factor authentication where it is offered. Be cautious with unexpected emails or texts referencing Romwe, Shein, or package deliveries, and do not click links in them. Watch your financial statements and credit reports for activity you did not authorize. If you received a notification from Romwe, activate the identity theft protection services that were offered.
In the news
- New York Attorney General, Assurance of Discontinuance re: Zoetop (PDF)ag.ny.gov (opens in a new tab)
- Romwe Data Security Incident FAQsm.romwe.com (opens in a new tab)
- The Register, "Zoetop pays $1.9m to settle customer data theft case"theregister.com (opens in a new tab)
- Communications Daily, "Class Action Alleges Romwe.com Hid Data Breach Fallout for 2 Years"communicationsdaily.com (opens in a new tab)
