← ASOS

2026 ASOS — Jul 28–29 credential stuffing / account takeover; ~138.8K customers (trade press)

2026 138.8K records affected Share on X

Data compromised

Name, email, delivery/billing address, telephone number, redacted payment card details (cardholder name, last four digits, expiration), associated social-media account details (not login credentials), and date of birth where stored

Technical writeup

Verified ASOS US Sales LLC / ASOS.com Limited customer notice via California AG filing sb24-628646 — letters dated August 21, 2026. ASOS detected unusual account activity on July 28, 2026 and on July 29 confirmed an unauthorized party may have accessed accounts using credentials obtained outside ASOS. On July 29 the security team blocked affected accounts and forced password resets; customers were emailed July 30. Exposed account data may include names, emails, addresses, phones, dates of birth, linked social-media details (not credentials), and redacted card data (name, last four, expiry). Suspicious transactions on a small number of accounts were blocked or canceled. CyberInsider cites ~138,828 affected individuals from a Srourian Law Firm investigation notice; state AG slices (e.g. Texas filings cited in trade press around ~9.4K) are smaller and may not be a global total. recordsAffected 138828 from CyberInsider/Srourian count; companyConfirmed true for the account-takeover incident.

Root cause

Unauthorized third party accessed ASOS customer accounts using login credentials obtained from a source outside ASOS (credential stuffing), detected July 28 and confirmed July 29, 2026

References