Zoetop Business Co. Ltd.
ent_d7dd131e64ef2f00905bbb4e
Disclosures
4
State AG · 4 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
7,341,382
as filed · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Zoetop Business Co. Ltd.
- Normalized
- zoetop business— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- 🦞Maine State AGas victim2020-12-31
Zoetop Business Co. Ltd., operator of the e-commerce website ROMWE, discovered that customer usernames and passwords were found on the dark web. The breach, which occurred on July 14, 2018, was discovered on September 7, 2020, and affected 7,341,382 individuals. The company responded by forcing password resets for affected customers and offering 12 months of identity theft protection services through ID Experts.
- 🦫Oregon State AGas victim2020-12-30
Zoetop Business Co. Ltd. reported a data breach to the Oregon Attorney General. The breach was reported on 2020-12-30. The breach occurred during 7/14/2018. The breach was discovered on 9/7/2020. 7,341,382 individuals were affected. Notice was sent on 12/30/2020.
- 💎Delaware State AGas reporting2020-12-30
ROMWE, operated by Zoetop Business Co. Ltd, disclosed that customer usernames and passwords were stolen from its network in July 2018 and discovered on September 7, 2020. The incident involved unauthorized access and exfiltration of credentials and basic PII (name, email, phone). ROMWE forced password resets and offered 12 months of identity theft protection services to affected customers across multiple US states.
- 🌲Washington State AGas victim2020-12-30
Zoetop Business Co. Ltd., a business sector entity reported a unclear/unknown incident to the Washington Attorney General. The organization became aware of the incident on 2020-09-07 and filed notice on 2020-12-30. 148,785 Washington residents were affected. 114 days elapsed between awareness and notification. 799 days to identify the breach.