HackingStolen CredentialsData ExfiltratedTargetedPIICREDENTIALSHighActive
Shein USA
bd_2f259e9c064b4d1f · schema v1 · pii pii-v1
Full breach record for Shein USA →SHEIN notified customers of a data breach affecting approximately 6.42 million individuals. The incident, occurring between June and August 2018, involved unauthorized access to customer email addresses and encrypted passwords. SHEIN engaged forensic investigators, removed malware, closed backdoors, and offered one year of identity theft monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed6,420,000 affectedView incident
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Business%20Resources%20Laws/Related%20Laws/Breaches/2018/Shein.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 15, 2018
- Raw hash
- d0f352063fd3c7ba24a79fc477a88f04060cf5dbac60243ae41d946e35cab0aa
Reporting entity
- Name
- Shein USAnorm: shein usa
- Domain
- shein-usa.com
Victim entity
- Name
- Shein USAnorm: shein usa
- Domain
- shein-usa.com
Incident
- Discovered
- Aug 22, 2018
- Materiality determined
- —
- Notification sent
- Sep 21, 2018
- Affected individuals
- 6,420,000
- Data types
- PIICREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notifying proper authorities
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(54 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.