ASOS Warns of Customer Account Access Due to Compromised Login Credentials
Fashion retailer ASOS has alerted customers to unauthorized access to their accounts, likely resulting from credential stuffing attacks that leveraged externally sourced login information.

ASOS US Sales LLC has reported a security incident where unauthorized third parties gained access to customer accounts using compromised login credentials. The incident, detected on July 28, 2026, and confirmed the following day, involved credentials that were obtained from sources outside of ASOS, indicating a probable credential-stuffing or account-takeover (ATO) attack. This method relies on threat actors testing username and password combinations previously leaked from other data breaches against ASOS accounts, exploiting users who reuse passwords across multiple online services.
The investigation by ASOS revealed that the compromised accounts may have exposed sensitive personal information. This includes customer names, email addresses, delivery and billing addresses, telephone numbers, and dates of birth. Additionally, details related to linked social media accounts were potentially accessed, though ASOS clarified that social media login credentials themselves were not involved in the breach. The company also stated that redacted payment card information, such as the cardholder's name, the last four digits of the card number, and its expiration date, may have been accessed. Crucially, ASOS emphasized that full payment card numbers and CVV codes were not compromised, nor were ASOS account passwords directly exposed through this incident.
In response to the detected unauthorized activity, ASOS took immediate action. On July 29, 2026, the company blocked access to all affected accounts and initiated a mandatory password reset process for these users. Customers were notified via email on July 30, 2026, requiring them to create new passwords before they could regain access to their accounts. This proactive measure aimed to secure the accounts and prevent further unauthorized access.
ASOS also identified that a small subset of the affected accounts exhibited signs of suspicious transactions. However, the company stated that its security controls successfully blocked these transactions, or they were canceled by ASOS's fraud team. No further unauthorized activity was detected after these containment measures were implemented, suggesting the attackers' ability to monetize the compromised accounts was limited.
This incident underscores the persistent and significant threat posed by credential stuffing and password reuse. Even when a company's own systems are not directly breached, stolen credentials from other services can serve as a gateway for attackers to access valuable personal data, including addresses and partial payment details. The reliance on externally sourced credentials highlights the interconnectedness of online security and the responsibility of users to maintain strong, unique passwords across different platforms.
ASOS has advised affected customers to reset their ASOS passwords and, importantly, to change passwords on other online services, particularly for critical accounts such as email, banking, payment platforms, and social media. The company also strongly recommended enabling multi-factor authentication (MFA) wherever available, as this adds a crucial layer of security against account takeovers. Furthermore, customers are urged to monitor their payment account activity and statements for any unusual or unauthorized transactions.
To further assist customers in protecting their identity, ASOS pointed them towards obtaining free annual credit reports from the three major US credit reporting agencies: Equifax, Experian, and TransUnion. Customers also have the option to place a fraud alert or a credit freeze on their credit files if they suspect any misuse of their personal information. The notification also confirmed that the company's communication to California residents was not delayed by law enforcement investigations, adhering to prompt disclosure requirements.
The incident serves as a stark reminder for both consumers and businesses about the ongoing challenges in cybersecurity. For consumers, it emphasizes the critical need for robust password hygiene and the adoption of security best practices like MFA. For retailers, it highlights the importance of continuous monitoring for suspicious login activity and the implementation of effective measures to detect and mitigate credential-based attacks, even when the initial compromise occurs elsewhere.