
ASOS is notifying US customers that attackers gained unauthorized access to accounts using credentials obtained outside the company.
This access potentially exposed personal, contact, and partial payment card information. According to an investigation published by Srourian Law Firm, the incident affected approximately 138,828 individuals.
In breach notification letters dated August 21, 2026, ASOS US Sales LLC said it detected unusual activity involving customer accounts on July 28 and began investigating immediately. By July 29, the online retailer had determined that an unauthorized third party may have accessed affected accounts with login credentials sourced from outside ASOS. Such incidents can occur when credentials stolen or leaked from unrelated services are reused against accounts on other platforms.
ASOS is a major online fashion and cosmetics retailer serving customers internationally through ASOS.com. The company sells clothing, footwear, accessories, and beauty products from its own labels and third-party brands, with ASOS US Sales LLC handling parts of its US operations.
According to the company's notification, attackers may have accessed information stored in compromised accounts, including customers':
- Names
- Email addresses
- Delivery or billing addresses
- Telephone numbers
- Dates of birth
- Details of linked social media accounts (no login credentials)
- Payment card information (cardholder's name, the final four digits of the card number, and the card's expiration date)
The notification does not indicate that complete payment card numbers or security codes were exposed.
Srourian Law Firm, which published an investigation notice on August 21, says 138,828 individuals were affected by the breach. Its notice lists names, addresses, financial information, dates of birth, and other personal details among the information involved.
ASOS said its security operations team blocked access to affected accounts on July 29 and forced mandatory password resets. Customers were emailed on July 30 informing them that their passwords needed to be changed.
The retailer also detected suspicious transactions on a small number of accounts. ASOS said some transactions were automatically blocked, while others were manually canceled by its fraud team. The company says it has observed no additional unauthorized activity since taking those measures.
The incident creates risks beyond unauthorized purchases because exposed identity and contact information can be used for phishing, social engineering, and identity fraud. Partial card information combined with a person's name, address, phone number, date of birth, and email address can also make fraudulent communications appear more convincing.
Affected customers should reset their ASOS password and, more importantly, change it anywhere else the same password was reused. Unique passwords generated and stored in a password manager can prevent credentials compromised at one service from being used to access another.
ASOS is also advising customers to monitor payment accounts and statements for unfamiliar activity. US customers concerned about identity theft can review their credit reports through AnnualCreditReport.com and consider placing a free fraud alert or credit freeze with Equifax, Experian, and TransUnion.






Leave a Reply