ASOS Warns Customers of Credential Stuffing Attack
Key Takeaways ASOS US Sales LLC detected unauthorized access to customer accounts on July 28, 2026. The incident is attributed to a credential stuffing attack, leveraging credentials obtained from...
Key Takeaways
- ASOS US Sales LLC detected unauthorized access to customer accounts on July 28, 2026.
- The incident is attributed to a credential stuffing attack, leveraging credentials obtained from third-party breaches.
- Potentially exposed data includes names, email addresses, delivery/billing details, phone numbers, dates of birth, social media account links, and redacted payment card information.
- ASOS has blocked affected accounts, initiated mandatory password resets, and mitigated suspicious transactions.
ASOS Confirms Credential Stuffing Attack on Customer Accounts
ASOS US Sales LLC has disclosed an incident involving unauthorized access to customer accounts, which the company identified on July 28, 2026, and officially confirmed the following day. The breach notification, dated August 21, 2026, details that an investigation was launched immediately after unusual account activity was detected.
Table Of Content
Nature of the Attack
The online fashion retailer concluded that an unauthorized third party likely exploited credentials acquired from external sources to log into customer accounts. This pattern of activity strongly suggests a credential stuffing or account takeover attack, rather than a direct compromise of ASOS’s internal authentication systems. Such attacks capitalize on the widespread practice of password reuse, where threat actors test previously leaked username and password combinations against various online services.
Exposed Customer Data
The information potentially accessed during the incident includes a range of personal details such as customer names, email addresses, shipping and billing addresses, telephone numbers, dates of birth, and links to social media accounts. ASOS explicitly stated that social media login credentials themselves were not compromised. Additionally, redacted payment card information, specifically the cardholder’s name, the last four digits of the card number, and its expiration date, may have been exposed. Crucially, ASOS confirmed that full payment card numbers, CVV codes, or ASOS account passwords were not directly compromised or exposed as part of this incident.
Company Response and Mitigation
Upon confirming the unauthorized access on July 29, 2026, ASOS promptly blocked access to all affected accounts and enforced mandatory password resets for these users. The company communicated this action to customers via email on July 30, requiring them to establish new passwords before they could regain access to their accounts. ASOS also noted that a limited number of accounts exhibited signs of suspicious transactions. According to ASOS US Sales LLC, these transactions were successfully blocked by existing security protocols or canceled by their fraud prevention team, with no further unauthorized activity detected following the implementation of containment measures. The notification to California residents was not delayed by law enforcement.
Ongoing Risk and Recommendations
This incident underscores the persistent danger posed by password reuse across different online platforms. Even when a company’s own systems remain secure, credentials stolen from other services can be leveraged to gain unauthorized entry to accounts containing sensitive personal information, addresses, and partial payment data. This type of attack highlights the critical need for robust personal cybersecurity practices.
What You Should Do
- Reset ASOS Password: Immediately change your password for your ASOS account to a strong, unique password that you do not use for any other service.
- Update Other Passwords: If you have reused your ASOS password on other websites, especially for email, banking, payment platforms, or social media, change those passwords immediately.
- Enable Multi-Factor Authentication (MFA): Activate MFA on your ASOS account and any other online services where it is available to add an extra layer of security.
- Monitor Financial Accounts: Regularly review your payment account activity and bank statements for any unfamiliar or suspicious transactions.
- Credit Monitoring: Consider obtaining free annual credit reports from Equifax, Experian, and TransUnion. If you suspect identity theft, placing a fraud alert or credit freeze on your credit files is advisable.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.