ASOS says attackers used login credentials obtained outside the company to access customer accounts, exposing personal information belonging to an estimated 138,828 people.
The retailer detected unusual activity on July 28 and confirmed unauthorized access the following day. The attack is consistent with credential stuffing or account takeover, in which credentials stolen from another service are reused against a different platform, according to Cyber Insider.
ASOS said the exposed information may have included names, email addresses, delivery and billing addresses, phone numbers, dates of birth, and details of linked social media accounts. Social media login credentials were not involved.
The notification also lists limited payment-card information: the cardholder’s name, last four digits and expiration date. ASOS did not indicate that complete card numbers or security codes were exposed.
ASOS response and timeline
ASOS blocked access to affected accounts and required password resets on July 29, one day after detecting unusual activity. Customers received emails on July 30 instructing them to create new passwords.
For a small number of accounts showing suspicious transactions, ASOS said the transactions were either blocked automatically or canceled by its fraud team.
The company said it had seen no additional unauthorized activity after taking those steps. Its public notification was dated Aug. 21, roughly three weeks after the initial containment.
The bigger risk may be password reuse
The incident shows why credential-stuffing attacks remain particularly troublesome for retailers: attackers do not necessarily need to break into a company’s systems when customers reuse passwords elsewhere.
Cyber Security News described the incident as consistent with attackers testing previously leaked username-password combinations against ASOS accounts. The external source of the credentials has not been identified. That creates a difficult security problem for both businesses and consumers. A retailer can strengthen its own defenses, but it cannot control whether customers reuse passwords stolen from another service.
What affected customers should do
Customers should create a new, unique ASOS password and change the same password anywhere else it was reused. They should also review order histories, saved addresses and payment methods for unexpected changes and monitor bank and payment statements.
ASOS recommends that affected U.S. customers review their credit reports and consider a fraud alert or credit freeze if they suspect identity misuse.
The lack of full payment-card numbers and security codes may reduce the immediate risk of card fraud, but the exposed names, addresses, phone numbers, dates of birth, and partial card details could still help attackers craft more convincing phishing and social-engineering attempts.
Other News: ToxicPanda 2.0 is targeting 349 financial apps across 16 countries while abusing Android VPN, Accessibility, and Wireless Debugging features to gain deeper control over infected devices.





