ASOS US Sales LLC has warned customers about unauthorized access to some accounts after attackers used login credentials obtained from outside the company.
The activity was detected on July 28, 2026, and ASOS confirmed the incident the following day. The company launched an investigation and found that an unauthorized party may have used previously exposed usernames and passwords to access customer accounts.
The incident appears to involve credential stuffing, where attackers test stolen login details from other websites against new services. This type of attack often succeeds when people reuse the same password across multiple accounts.
Customer Accounts Were Accessed
According to ASOS, the information that may have been accessed varies by account. It could include names, email addresses, delivery or billing addresses, phone numbers, dates of birth, and information connected to social media accounts.
Some payment information may also have been visible, including the cardholder’s name, last four digits of the card, and expiration date.
ASOS said there is no indication that full card numbers, CVV codes, or ASOS account passwords were exposed.
The company moved quickly to contain the incident. On July 29, it blocked access to affected accounts and required customers to reset their passwords. Customers were notified by email on July 30.
ASOS also found suspicious transactions on a small number of accounts. The company said its security systems or fraud team blocked or canceled those transactions, and no further unauthorized activity was identified after containment.
Password Reuse Remains a Major Risk
The incident highlights how attackers can take over accounts even when a company itself has not suffered a direct password database breach.
When credentials from an unrelated data breach are reused on another website, attackers can try those same combinations automatically. A successful login can then expose personal information or potentially lead to fraudulent purchases.
Customers affected by the incident should:
- Create a new, unique ASOS password
- Change the same password on other websites where it was reused
- Enable multi-factor authentication whenever available
- Review bank and payment accounts for unusual activity
Users should pay particular attention to their email, banking, payment, and social media accounts, as these can provide attackers with access to additional services.
Customers who are concerned about possible identity misuse can also review their credit reports and consider additional protections such as a fraud alert or credit freeze.
The ASOS incident is another reminder that password reuse can turn an old data breach into a new account takeover. Using unique passwords and multi-factor authentication can significantly reduce the risk of attackers successfully accessing multiple accounts