ASOS has started notifying affected customers in the U.S. after detecting unauthorized access to accounts linked to login credentials obtained from outside its systems.
According to a breach notification issued by ASOS US Sales LLC, unusual activity was detected in certain ASOS accounts on July 28, 2026.
An investigation conducted the following day revealed that an unauthorized third party may have accessed these accounts using credentials from external sources.
The notification does not specify the source of the credentials, the number of affected customers, or who was responsible for the activity.
This incident highlights the ongoing risk of account takeover attacks, in which threat actors use credentials exposed in unrelated data breaches, through phishing campaigns, malware, or password reuse.
Rather than exploiting a vulnerability within ASOS’s infrastructure, this situation involved the abuse of valid account credentials, typical of credential stuffing and password-reuse attacks.
Customer Data Potentially Exposed
ASOS stated that the accessed account information may have included customer names, email addresses, delivery and billing addresses, telephone numbers, dates of birth, and details of associated social media accounts. The company clarified that social media login credentials were not compromised.
The potentially exposed payment information was limited to redacted card details, including the cardholder’s name, the last four digits of the card, and its expiration date. ASOS confirmed that full payment card numbers, CVV values, or payment credentials were not compromised in this incident.
While redacted payment data alone is generally insufficient for traditional card-not-present fraud, the combination of personal and account information could facilitate convincing phishing, social engineering, or identity fraud attempts.
Attackers might impersonate ASOS support by referencing an affected customer’s partial card information or address to obtain replacement credentials or payment data.
ASOS’s security operations team blocked access to the affected accounts and enforced mandatory password resets on July 29. Customers received email notifications on July 30, instructing them to reset their passwords.
For a small number of accounts where suspicious transactions were detected, ASOS either automatically blocked them or manually canceled them through its fraud team. The company reported that no further unauthorized activity had been observed after implementing these response measures.
The quick action indicates that ASOS moved to contain the activity within approximately one day of detecting the unusual account behavior. However, the public notification was dated August 21, over three weeks after the initial detection.
Affected customers should reset their ASOS passwords immediately and avoid reusing those passwords on other sites. If the same password was used elsewhere, those accounts should also be updated right away, prioritizing email, banking, payment, and social media services.
Customers are advised to:
- Review ASOS order history, saved addresses, and payment methods for any unauthorized changes.
- Monitor bank and card statements for unfamiliar transactions.
- Be vigilant about ASOS-themed phishing messages asking for passwords, payment details, or one-time codes.
- Use unique passwords stored in a password manager.
- Enable multi-factor authentication where available.
ASOS also encourages customers to review their credit files, consider placing a fraud alert, and use a credit freeze if they suspect their personal information has been misused.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC





