← Back to feed
PhishingEmerging1 sourceAug 25, 2026 · 10:11via CyberPress

Hackers Access ASOS Customer Accounts Using Stolen Login Credentials

Brief

ASOS has notified affected U. S. customers that an unauthorized party accessed some accounts using login credentials obtained from outside the online fashion retailer.

The incident, detected on July 28, 2026, underscores the operational risk of credential-stuffing attacks against consumer platforms. ASOS US Sales LLC said it identified unusual activity involving customer accounts on July 28 and opened an investigation.

A day later, on July 29, the company confirmed that an unauthorized third party may have accessed accounts using externally sourced credentials, not through a confirmed compromise of ASOS systems.

Hackers Access ASOS Customer Accounts

The wording points to account takeover (ATO), where attackers test previously exposed username-and-password pairs against another service.

Read more on CyberPress