Spoofing Shein for Credential Harvesting - Check Point Blog (2024)

Shein is one of the most popular shopping apps in the world. In fact, it’s the second most downloaded shopping app globally, with over 251 million downloads.

The e-commerce platform is Googled more frequently than major brands like Nike and adidas.

Shein gained popularity for its inexpensive clothing and low prices. However, the company has faced significant criticism for its poor human rights record.

Additionally, according to a TIME report, Shein has been exploited by scammers in various ways, including the use of fake gift cards on Instagram and counterfeit websites.

That brings us to the focus of today’s report. Researchers from Harmony Email will discuss how hackers are impersonating Shein in an effort to steal user credentials. Over the last month, they have identified more than 1,000 of these fraduluent emails.

Email Example

Spoofing Shein for Credential Harvesting - Check Point Blog (1)

The email arrives with a tempting subject line: “Order Verification SHEIN” – claiming to be from Shein customer service. But a closer look reveals a red flag – the sender’s email address doesn’t match Shein’s official one.

The email excitedly announces you’ve received a mystery box from Shein. However, the included link won’t bring you a surprise gift; it leads to a fake website designed to steal your personal information (a credential harvesting site).

This phishing attempt is quite transparent. It preys on your excitement by claiming you’ve won a prize and uses the trusted brand name “Shein” to gain your trust. However, a vigilant user can easily spot the scam: check the sender’s email address (it shouldn’t be random letters) and verify that any links lead to legitimate Shein webpages.

Techniques

Just like other phishing attempts, scammers are trying to capitalize on popular brands and current trends to trick you. This time, they’re using Shein.

There are several red flags that this email isn’t legitimate. First, there’s a strong sense of urgency surrounding the “mystery box” offer, which is designed to create excitement and pressure you into clicking.

Another clue? The email address itself is a jumble of random letters, not a recognizable Shein address. You won’t find any Shein branding or logos in the email either. Finally, the link in the email won’t take you to an official Shein webpage, but to a fraudulent website designed to steal your information.

Over the last month, we’ve seen over 1,000 of these attacks.

  • Make sure you don’t click on links from websites whose address isn’t the official one and check the email’s source.
  • Check the address of the website and the sender’s name for spelling and punctuation errors on websites that look real.
  • Ensure the email is free of spelling errors. Pay attention to the language in the email: are you expecting to be addressed in this language by your shipping company?
Spoofing Shein for Credential Harvesting - Check Point Blog (2024)

FAQs

Is there a fake Shein website? ›

You won't find any Shein branding or logos in the email either. Finally, the link in the email won't take you to an official Shein webpage, but to a fraudulent website designed to steal your information. Over the last month, we've seen over 1,000 of these attacks.

What is the privacy issue with Shein? ›

In 2018, Shein suffered a data breach in which the login details of 39 million accounts were stolen and sold online. Shein's parent company, Zoetop, was later fined $1.9 million because it notified only a fraction of the affected customers about the breach.

What is the Shein scandal? ›

Artists have filed a racketeering lawsuit accusing it of stealing designs. A congressional report says Shein abuses a loophole in import tax laws. Lawmakers have called for an investigation into alleged use of forced labor.

How to get free clothes from Shein? ›

You'll have a chance to receive free clothes if selected, and we ask that you post a detailed review about the overall experience of the clothing item you receive, including quality, style, fit, fabric, and construction. This helps our customers see detailed personal reviews from other fellow customers.

Is shein selling fake? ›

Artists have accused Shein of stealing their work to create products, and brands like Oakley and Ralph Lauren have sued Shein for violating their intellectual property rights.

Why is shein so cheap? ›

Outsourcing labor

One of the key ways that Shein and other fast-fashion brands keep prices low is by outsourcing manufacturing labor to cheaper markets, said Dana Thomas, a Paris-based fashion journalist and author of “Fashionopolis: The Price of Fast Fashion and the Future of Clothes.”

Is there a catch with Shein? ›

Only for pieces you won't wear often

With Shein, you get what you pay for: low-cost, trendy clothes that can be hit or miss when it comes to actual quality. It's the online-only equivalent of mall stores like Forever 21, H&M, and Zara.

Is this website legit to buy from? ›

Check if it is authenticated (HTTP Secure): Authenticated websites begin with https:// instead of http://. Most illegitimate sites do not bother getting security certification because they are shut down quickly. Confirming the https:// is especially important on pages where you submit payment information.

Top Articles
Latest Posts
Article information

Author: Zonia Mosciski DO

Last Updated:

Views: 6023

Rating: 4 / 5 (71 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Zonia Mosciski DO

Birthday: 1996-05-16

Address: Suite 228 919 Deana Ford, Lake Meridithberg, NE 60017-4257

Phone: +2613987384138

Job: Chief Retail Officer

Hobby: Tai chi, Dowsing, Poi, Letterboxing, Watching movies, Video gaming, Singing

Introduction: My name is Zonia Mosciski DO, I am a enchanting, joyous, lovely, successful, hilarious, tender, outstanding person who loves writing and wants to share my knowledge and understanding with you.