ASOS Account Takeover Attack Exposes Data of 138,828 Customers

ASOS says attackers used credentials stolen elsewhere to access customer accounts, exposing personal data belonging to an estimated 138,828 people.

Aug 26, 2026
2 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

ASOS says attackers used login credentials obtained outside the company to access customer accounts, exposing personal information belonging to an estimated 138,828 people.

The retailer detected unusual activity on July 28 and confirmed unauthorized access the following day. The attack is consistent with credential stuffing or account takeover, in which credentials stolen from another service are reused against a different platform, according to Cyber Insider.

ASOS said the exposed information may have included names, email addresses, delivery and billing addresses, phone numbers, dates of birth, and details of linked social media accounts. Social media login credentials were not involved.

The notification also lists limited payment-card information: the cardholder’s name, last four digits and expiration date. ASOS did not indicate that complete card numbers or security codes were exposed.

ASOS response and timeline

ASOS blocked access to affected accounts and required password resets on July 29, one day after detecting unusual activity. Customers received emails on July 30 instructing them to create new passwords.

For a small number of accounts showing suspicious transactions, ASOS said the transactions were either blocked automatically or canceled by its fraud team.

The company said it had seen no additional unauthorized activity after taking those steps. Its public notification was dated Aug. 21, roughly three weeks after the initial containment.

The bigger risk may be password reuse

The incident shows why credential-stuffing attacks remain particularly troublesome for retailers: attackers do not necessarily need to break into a company’s systems when customers reuse passwords elsewhere.

Cyber Security News described the incident as consistent with attackers testing previously leaked username-password combinations against ASOS accounts. The external source of the credentials has not been identified. That creates a difficult security problem for both businesses and consumers. A retailer can strengthen its own defenses, but it cannot control whether customers reuse passwords stolen from another service.

Advertisement

What affected customers should do

Customers should create a new, unique ASOS password and change the same password anywhere else it was reused. They should also review order histories, saved addresses and payment methods for unexpected changes and monitor bank and payment statements.

ASOS recommends that affected U.S. customers review their credit reports and consider a fraud alert or credit freeze if they suspect identity misuse.

The lack of full payment-card numbers and security codes may reduce the immediate risk of card fraud, but the exposed names, addresses, phone numbers, dates of birth, and partial card details could still help attackers craft more convincing phishing and social-engineering attempts.

Other News: ToxicPanda 2.0 is targeting 349 financial apps across 16 countries while abusing Android VPN, Accessibility, and Wireless Debugging features to gain deeper control over infected devices. 

AA

Aminu Abdullahi is an experienced B2B technology and finance writer. He has written for various publications, including TechRepublic, eWEEK, Enterprise Networking Planet, eSecurity Planet, CIO Insight, Enterprise Storage Forum, IT Business Edge, Webopedia, Software Pundit, Geekflare and more.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.