ASOS Data Breach Exposes Customer Details After Stolen Credential Attacks

ASOS confirmed attackers used credentials obtained outside the company to access customer accounts containing personal information and limited payment card details.
ASOS logo over a darkened fashion retail checkout counter with a computer displaying a security lock, illustrating the ASOS customer data breach.

Online fashion retailer ASOS has disclosed a data breach affecting some U.S. customers after attackers accessed accounts using login credentials obtained outside the company.

ASOS detected unusual account activity on July 28, 2026, and confirmed the following day that an unauthorized third party may have accessed customer accounts. The company disclosed the incident to the California Attorney General on Aug. 21.

The potentially exposed information varies by account but may include names, email addresses, delivery and billing addresses, telephone numbers, dates of birth, details about linked social media accounts, and limited payment card information.

The payment information was redacted and limited to the cardholder name, last 4 digits of the card number and expiration date, according to ASOS. The company said social media login credentials were not exposed.

Stolen credentials opened the door to ASOS accounts

ASOS said the credentials used to access affected accounts came from a source outside its systems. That detail points to an account takeover scenario involving previously compromised credentials rather than attackers obtaining ASOS passwords through a breach of the retailer’s own credential store.

The company has not disclosed how the attackers acquired the credentials or whether they originated from previous third-party breaches, phishing, malware or another source.

Credential reuse can allow attackers to take passwords exposed elsewhere and test them against unrelated services. ASOS already advises customers to use a unique password for their ASOS accounts because credentials stolen from another service can potentially be reused to access additional accounts.

Suspicious transactions detected on a small number of accounts

ASOS blocked access to affected accounts on July 29 and imposed mandatory password resets. Customers were notified the following day that they would need to choose new passwords.

The retailer also found evidence of suspicious transactions involving a small number of accounts. ASOS said some transactions were automatically blocked, while its fraud team manually canceled others.

The company said it has not observed additional unauthorized activity since implementing those measures.

ASOS has not publicly disclosed how many customer accounts were affected. The company’s breach notification filed with the California Attorney General lists July 28 as the date of the breach.

Exposed profile data could fuel follow-on scams

Although full payment card numbers were not included in the information ASOS says may have been accessed, the combination of contact details, addresses, dates of birth and partial card information could still be useful for social engineering.

An attacker with knowledge of a customer’s ASOS account details could potentially construct convincing phishing messages or impersonate the retailer while referencing information that makes the communication appear legitimate.

ASOS separately warns that scammers impersonate the company through social media, fraudulent email accounts, messaging services and fake websites. Customers should therefore be cautious of unexpected messages claiming to relate to the breach or their ASOS accounts.

The company recommends that affected customers monitor payment accounts and statements for unusual activity. Its breach notification also provides information about obtaining credit reports and placing fraud alerts or credit freezes.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site