ASOS US Sales LLC has confirmed that customer accounts were accessed by a third party leveraging login credentials stolen from elsewhere. The issue was first detected on July 28, 2026, and officially confirmed the following day after ASOS noticed unusual account activity and initiated an investigation.
What Happened
The company’s inquiry revealed that unauthorized actors used credentials obtained from outside ASOS systems—pointing to account takeover or credential stuffing rather than a breach of ASOS’s own authentication infrastructure. In credential stuffing, attackers test already compromised usernames and passwords across services, exploiting password reuse.
Data exposed in affected accounts include personal and contact details such as names, email addresses, billing/delivery addresses, phone numbers, dates of birth, and social media profiles tied to those accounts. Payment card data disclosed was limited to redacted information—cardholder name, last four digits, and expiration date. Crucially, no full card numbers, CVV codes, or ASOS account passwords were reported compromised.
Aftermath and Response
On July 29, ASOS locked down the impacted accounts and issued mandatory password resets. Users were informed via email on July 30 that they must set new passwords before regaining access. A small subset of accounts showed signs of suspicious purchases, but ASOS’s security systems or fraud team intervened to block or cancel those transactions. No further unauthorized access was observed following the containment actions.
The warning emphasizes the persistent threat posed by password reuse. Even without a breach in a company’s own systems, credentials exposed elsewhere can enable attackers to access accounts elsewhere—where personal and financial information is stored. ASOS is urging affected customers to change their passwords (especially on sites where the same one is used), monitor payment accounts for unauthorized activity, and enable multi-factor authentication wherever possible. They also recommend obtaining free annual credit reports and considering fraud alerts or credit freezes for potential identity misuse. Notice to California customers was made without delay as required by law enforcement considerations.
What this means: This incident underlines the risks users face when reusing credentials across platforms—and why companies need strong authentication safeguards. ASOS’s swift action helped contain damage, but the episode should prompt all users to rethink password hygiene. Going forward, ASOS and its peers must ensure better protections around login security—multi-factor authentication, monitoring for anomalous logins, and educating users on secure passwords will be essential.