← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 25, 2026 · 14:15via Cyber Security News

ASOS Warns Customer Accounts Were Accessed Using Compromised Login Credentials

Brief

ASOS US Sales LLC reported unauthorized access to customer accounts using credentials obtained from outside the company, detected on July 28 and confirmed the next day.

In a breach notification dated August 21, 2026, ASOS said it identified unusual activity involving customer accounts and launched an investigation immediately.

The retailer determined that an unauthorized third party may have used externally sourced credentials to sign in to affected accounts. The wording indicates a credential-stuffing or account-takeover scenario rather than a direct compromise of ASOS authentication infrastructure.

In such attacks, threat actors test previously leaked username-password pairs against other online services, relying on customers who reuse passwords across multiple platforms.

Read more on Cyber Security News