Monday, September 14, 2026

ASOS Warns Customers of Data Breach Following Credential-Based Account Takeovers

ASOS has started notifying affected customers in the U.S. after detecting unauthorized access to accounts linked to login credentials obtained from outside its systems.

According to a breach notification issued by ASOS US Sales LLC, unusual activity was detected in certain ASOS accounts on July 28, 2026.

An investigation conducted the following day revealed that an unauthorized third party may have accessed these accounts using credentials from external sources.

The notification does not specify the source of the credentials, the number of affected customers, or who was responsible for the activity.

This incident highlights the ongoing risk of account takeover attacks, in which threat actors use credentials exposed in unrelated data breaches, through phishing campaigns, malware, or password reuse.

Rather than exploiting a vulnerability within ASOS’s infrastructure, this situation involved the abuse of valid account credentials, typical of credential stuffing and password-reuse attacks.

Customer Data Potentially Exposed

ASOS stated that the accessed account information may have included customer names, email addresses, delivery and billing addresses, telephone numbers, dates of birth, and details of associated social media accounts. The company clarified that social media login credentials were not compromised.

The potentially exposed payment information was limited to redacted card details, including the cardholder’s name, the last four digits of the card, and its expiration date. ASOS confirmed that full payment card numbers, CVV values, or payment credentials were not compromised in this incident.

While redacted payment data alone is generally insufficient for traditional card-not-present fraud, the combination of personal and account information could facilitate convincing phishing, social engineering, or identity fraud attempts.

Attackers might impersonate ASOS support by referencing an affected customer’s partial card information or address to obtain replacement credentials or payment data.

ASOS’s security operations team blocked access to the affected accounts and enforced mandatory password resets on July 29. Customers received email notifications on July 30, instructing them to reset their passwords.

For a small number of accounts where suspicious transactions were detected, ASOS either automatically blocked them or manually canceled them through its fraud team. The company reported that no further unauthorized activity had been observed after implementing these response measures.

The quick action indicates that ASOS moved to contain the activity within approximately one day of detecting the unusual account behavior. However, the public notification was dated August 21, over three weeks after the initial detection.

Affected customers should reset their ASOS passwords immediately and avoid reusing those passwords on other sites. If the same password was used elsewhere, those accounts should also be updated right away, prioritizing email, banking, payment, and social media services.

Customers are advised to:

  • Review ASOS order history, saved addresses, and payment methods for any unauthorized changes.
  • Monitor bank and card statements for unfamiliar transactions.
  • Be vigilant about ASOS-themed phishing messages asking for passwords, payment details, or one-time codes.
  • Use unique passwords stored in a password manager.
  • Enable multi-factor authentication where available.

ASOS also encourages customers to review their credit files, consider placing a fraud alert, and use a credit freeze if they suspect their personal information has been misused.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor

China-linked threat actors tracked as UNC3569 have exploited a...

Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users

A Casbaneiro banking Trojan campaign targeting users across Latin...

AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process

A five-stage AsyncRAT campaign that chains a socially engineered...

Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data

Threat actors are increasingly using Claude-based AI workflows to...

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google...

New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets

A newly identified phishing campaign is abusing the legitimate...

Related Articles

Recent News