Do This Now

ASOS US reported a customer data breach. Freeze credit now

ASOS US Sales LLC dated customer notices 21 August 2026 after credential stuffing hit accounts on 28 and 29 July. This was not a dump of full card numbers from ASOS systems. Attackers used login passwords obtained somewhere else, then reached account data that can include name, email, addresses, phone, date of birth, redacted payment details (name, last four, expiry), and linked social account labels. If you shop ASOS in the US, change the ASOS password if you have not already, change that password everywhere you reused it, freeze credit, and treat surprise ASOS emails as suspect until you verify them.

Laptop on a home desk showing ASOS account password reset screen beside an opened August 2026 breach notice letter
Password first. Then freeze credit.

Overview

What broke

According to the California Attorney General notice for ASOS US Sales LLC, ASOS detected unusual account activity on Tuesday 28 July 2026. On Wednesday 29 July 2026 they confirmed an unauthorized party may have accessed accounts using login credentials obtained from a source outside ASOS. That pattern is credential stuffing: passwords leaked or stolen elsewhere, tried against ASOS until some matched.

Data that may have been accessed includes name; email address; delivery or billing address; telephone number; redacted payment card details (cardholder name, last four digits, expiration date); details of associated social media accounts but not those social login secrets; and date of birth. The notice does not describe bulk theft of full primary account numbers from an ASOS database. Do not read this brief as a full-PAN breach.

ASOS says it blocked access to affected accounts on 29 July, forced a mandatory password reset, and emailed customers on 30 July about that reset. Where they saw suspicious orders, automated blocks or fraud staff canceled them. They report no additional unauthorized activity after those steps. Individual state filings (for example Texas and Vermont counts reported in some coverage) describe subsets of residents; the California notice is the consumer primary for what happened and what to do.

Who is in range

You. ASOS US customers whose accounts were in the July stuffing wave, especially anyone who received the August 21 notice or the July 30 reset mail. If you reuse the same password on ASOS and other sites, treat those other sites as in range for a password change too.

Shoppers who never had an ASOS account can skip. Shoppers who already completed the forced reset, unique-passworded ASOS, froze credit, and watch statements are mostly done. Everyone else with an ASOS login should still verify.

What the vendor shipped

  • Account lock and mandatory password reset email on 30 July 2026.
  • Blocking or canceling suspicious transactions where they saw them.
  • August 21, 2026 written notices describing the incident and pointing customers to credit freezes, fraud alerts, AnnualCreditReport, and ASOS customer care.

ASOS customer care contact is listed on their US get-in-touch page in the notice. Primary paperwork for California residents sits on the AG breach report linked above.

What this is not

  • Not a confirmed bulk leak of full card PANs from ASOS storage.
  • Not fixed by freezing credit alone if the ASOS password is still an old reused string.
  • Not permission to trust random “ASOS refund” texts that ask for a one-time code.
  • Not a global victim total invented from one state’s filing. Use your notice and the CA description of what was accessed.
  • Not solved by deleting the app without changing the password on the web account.

Credential stuffing succeeds where password reuse succeeds. Break the reuse. Then freeze credit.

Do This Now card: Change ASOS password then freeze credit, in range You, urgency Today, then Password Equifax Experian TransUnion
Change the ASOS password. Then freeze credit.

Do This Now

In range: You. ASOS US account holders, especially with a July reset mail or August notice.

Urgency: Today. Stuffing turns reused passwords into account takeovers and follow-on fraud.

  1. Sign in at ASOS (or use the official reset mail from 30 July) and set a new unique password. Change that old password on every other site where you reused it.
  2. Freeze credit at Equifax, Experian, and TransUnion. Save the PINs.
  3. Watch bank and card statements, turn on transaction alerts, and treat unexpected ASOS refund or “verify your order” messages as phishing until you confirm them in the real ASOS account or app.

Who can skip

  • No ASOS account and no notice.
  • You already finished the mandatory reset, use a unique password and preferably app-based MFA where offered, froze all three bureaus, and monitor cards.
  • You only browse ASOS logged out and never stored an address or card on an account.

Why it matters

Credential stuffing is boring and effective. The attacker never needs to break ASOS cryptography if your Netflix-era password still opens the clothing account. Once inside, address, phone, DOB, and last-four card metadata are enough for convincing phishing and some fraud workflows.

ASOS moved quickly on locks and resets. That helps only if you completed the reset and stopped reusing the old secret. Credit freezes reduce the chance a parallel identity scam opens a new loan while you are distracted by a fake shipping email.

Password managers make this week easier. Generate a fresh ASOS password you will never reuse. If your manager shows the old ASOS secret on five other sites, fix those five the same evening. Stuffing campaigns often spray one leak across many retailers. ASOS may be the notice you received; it may not be the only account that shared the password.

Redacted card data still matters. Last four plus expiry plus name is enough for a convincing fake “confirm your ASOS order” page. It is not the same as a thief having the full PAN from ASOS storage. If your card issuer offers temporary virtual card numbers, consider rotating the card you store on fashion sites after any account-takeover notice.

July 30 reset mail and August 21 notice can arrive on different days to different people. If you got the reset but not the letter, still finish freezes. If you got the letter but already reset, still verify the password is unique and freeze credit. The two steps close different holes.

State AG counts that appear in news coverage are useful for scale gossip. They are not a substitute for the CA notice’s description of redacted card data and outside credentials. Stick to what the notice says.

The bottom line

Fix the ASOS login

  1. Open the official ASOS US site or app. Avoid search ads.
  2. If you still have the 30 July reset email from ASOS, use that link, or start Forgot password from the real site.
  3. Set a long unique password. Store it in a password manager.
  4. Enable any available extra login checks ASOS offers on your account.
  5. Review saved addresses and stored cards in the account. Remove anything you do not need.
  6. On every other site where that old password lived, change those passwords too.

Freeze credit and watch money

  1. Place freezes at Equifax, Experian, and TransUnion using the official freeze pages cited in the ASOS notice.
  2. Optional: place a fraud alert with one bureau.
  3. Pull a free credit report round from AnnualCreditReport on a staggered schedule.
  4. Turn on card transaction alerts. Dispute charges you do not recognize with the card issuer, not with a stranger in a DM.

Mail and phishing

Keep the August 21 notice if you received it. Expect copycat mail. Real ASOS help is reachable through the get-in-touch page named in the notice. Nobody from ASOS needs your password, remote-access software, or gift cards to “finish the breach process.”

If you cannot sign in

Use Forgot password on the official ASOS US site. Complete the reset email from ASOS domains you recognize from past orders. If the account stays locked, contact ASOS through the get-in-touch page named in the California notice and ask them to verify the August incident steps for your email. Do not grant screen-sharing to a stranger who messaged you first on Instagram about your “hacked ASOS.”

Parents and shared household logins: whoever owns the email on the ASOS account must do the reset. Then tell everyone who borrows the login the new password only through a safe channel, or better, stop sharing one shopping login.

What you should see

ASOS accepts only your new password. Other reused sites have new passwords too. All three bureaus show a freeze. Card alerts are on. No full card number was required from you to “verify” the incident.

When you are done

ASOS password is unique and changed. Reused passwords elsewhere are changed. Credit freezes are active. Statements are on your radar. You followed the California AG ASOS US notice without inventing full-PAN panic or fake victim totals. That is the job.

Send this to someone