ASOS Notifies U.S. Customers of Credential Stuffing Attack
ASOS US Sales LLC began notifying affected customers on July 30, 2026, after detecting unauthorized access to accounts linked to credentials obtained from external sources. The incident was identified on July 28, when unusual activity was observed in certain ASOS accounts. An investigation the following day confirmed that a third party had accessed these accounts using login details from unrelated breaches, phishing campaigns, or password reuse rather than exploiting a vulnerability in ASOS’s systems.
The exposed data may have included customer names, email addresses, delivery and billing details, phone numbers, dates of birth, and linked social media account information. While full payment card numbers and CVV values were not compromised, redacted card details such as the cardholder’s name, last four digits, and expiration date were potentially accessed. Though this limited payment data is insufficient for direct fraud, it could be used in phishing or social engineering attacks to extract further sensitive information.
ASOS’s security team responded swiftly, blocking access to affected accounts and enforcing mandatory password resets on July 29. Suspicious transactions were either automatically blocked or manually canceled by the fraud team, and no further unauthorized activity was detected after these measures. Despite the rapid containment, the public notification was issued on August 21, over three weeks after the initial detection.
The incident underscores the persistent threat of credential stuffing attacks, where attackers leverage stolen credentials from other breaches to gain unauthorized access. ASOS confirmed that no internal systems were compromised, attributing the breach solely to the misuse of valid account credentials.
Source: https://gbhackers.com/asos-warns-customers-of-data-breach/
ASOS.com cybersecurity rating report: https://www.rankiteo.com/company/asos-com
"id": "ASO1787660859",
"linkid": "asos-com",
"type": "Breach",
"date": "7/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Retail/Fashion',
'location': 'United States',
'name': 'ASOS US Sales LLC',
'type': 'E-commerce'}],
'attack_vector': 'Compromised credentials from external sources (unrelated '
'breaches, phishing, password reuse)',
'customer_advisories': 'Mandatory password resets, notification of potential '
'phishing risks',
'data_breach': {'personally_identifiable_information': 'Names, email '
'addresses, '
'delivery/billing '
'details, phone '
'numbers, dates of '
'birth, social media '
'account information',
'sensitivity_of_data': 'High (PII, partial payment data)',
'type_of_data_compromised': 'Personal identifiable '
'information, payment card '
'details (redacted)'},
'date_detected': '2026-07-28',
'date_publicly_disclosed': '2026-08-21',
'date_resolved': '2026-07-29',
'description': 'ASOS US Sales LLC began notifying affected customers on July '
'30, 2026, after detecting unauthorized access to accounts '
'linked to credentials obtained from external sources. The '
'incident was identified on July 28, when unusual activity was '
'observed in certain ASOS accounts. An investigation confirmed '
'that a third party had accessed these accounts using login '
'details from unrelated breaches, phishing campaigns, or '
'password reuse rather than exploiting a vulnerability in '
'ASOS’s systems.',
'impact': {'data_compromised': 'Customer names, email addresses, delivery and '
'billing details, phone numbers, dates of '
'birth, linked social media account '
'information, redacted payment card details '
'(cardholder name, last four digits, '
'expiration date)',
'identity_theft_risk': 'Potential for phishing or social '
'engineering attacks',
'payment_information_risk': 'Redacted card details could be used '
'in phishing/social engineering',
'systems_affected': 'Customer accounts'},
'investigation_status': 'Completed',
'lessons_learned': 'Persistent threat of credential stuffing attacks due to '
'password reuse and external breaches; importance of rapid '
'containment and customer communication.',
'post_incident_analysis': {'corrective_actions': 'Blocked affected accounts, '
'enforced password resets, '
'canceled suspicious '
'transactions, improved '
'monitoring for credential '
'reuse',
'root_causes': 'Use of compromised credentials '
'from external sources (unrelated '
'breaches, phishing, password '
'reuse)'},
'recommendations': 'Enforce multi-factor authentication, educate customers on '
'password hygiene, monitor for credential reuse, and '
'implement adaptive security measures.',
'references': [{'source': 'ASOS US Sales LLC customer notification'}],
'response': {'communication_strategy': 'Customer notifications issued on July '
'30, 2026, and public disclosure on '
'August 21, 2026',
'containment_measures': 'Blocked access to affected accounts, '
'enforced mandatory password resets, '
'canceled suspicious transactions',
'incident_response_plan_activated': 'Yes',
'remediation_measures': 'Mandatory password resets, fraud team '
'intervention'},
'title': 'ASOS Notifies U.S. Customers of Credential Stuffing Attack',
'type': 'Credential Stuffing'}