Zoetop Business Co. Ltd.
ent_d7dd131e64ef2f00905bbb4e
Disclosures
7
State AG · 7 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
7,341,382
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Zoetop Business Co. Ltd.
- Normalized
- zoetop business— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (7)newest first
- Hawaii State AGas victim2020-12-31
Zoetop Business Co. Ltd. (dba ROMWE) notified Hawaii OCP of a security incident where customer usernames and passwords stolen in July 2018 were discovered on the dark web in September 2020. Approximately 30,382 Hawaii residents were affected. ROMWE forced password resets and offered identity theft protection.
- Maine State AGas victim2020-12-31
Zoetop Business Co. Ltd., operator of the e-commerce website ROMWE, discovered that customer usernames and passwords were found on the dark web. The breach, which occurred on July 14, 2018, was discovered on September 7, 2020, and affected 7,341,382 individuals. The company responded by forcing password resets for affected customers and offering 12 months of identity theft protection services through ID Experts.
- New Hampshire State AGas victim2020-12-30
Zoetop Business Co. Ltd. (operating ROMWE) notified New Hampshire AG of a security incident affecting ~29,914 NH residents. Customer usernames and passwords stolen in July 2018 were discovered on the dark web on September 7, 2020. Account info (name, email, phone) was accessible; credit card data was not stored. Remediation included password resets and intrusion detection upgrades. Affected individuals received identity theft protection services.
- Montana State AGas victim2020-12-30
Zoetop Business Co. Ltd. (ROMWE) notified customers that usernames and passwords were stolen from its network in July 2018 and discovered on the dark web in September 2020. The breach exposed credentials and basic PII (name, email, phone). ROMWE forced password resets and offered 12 months of identity theft protection.
- Oregon State AGas victim2020-12-30
Zoetop Business Co. Ltd. reported a data breach to the Oregon Attorney General. The breach was reported on 2020-12-30. The breach occurred during 7/14/2018. The breach was discovered on 9/7/2020. 7,341,382 individuals were affected. Notice was sent on 12/30/2020.
- Delaware State AGas reporting2020-12-30
ROMWE, operated by Zoetop Business Co. Ltd, disclosed that customer usernames and passwords were stolen from its network in July 2018 and discovered on September 7, 2020. The incident involved unauthorized access and exfiltration of credentials and basic PII (name, email, phone). ROMWE forced password resets and offered 12 months of identity theft protection services to affected customers across multiple US states.
- Washington State AGas victim2020-12-30
Zoetop Business Co. Ltd. (ROMWE) notified Washington AG of a security incident where customer usernames and passwords stolen in July 2018 were found on the dark web. Discovered Sept 7, 2020, the breach affected ~148,785 WA residents. Data included names, emails, phones, and credentials. ROMWE forced password resets and offered identity theft protection.