Skip to main content
Emerging ThreatsData Breaches

ASUS eShop Breach Exposes Customer Order Data

Online store's packing area with shelving, packages, and blurred laptop screen.

“unauthorized access to part of the Asus eShop environment,” the company said

Asus has alerted customers that an intruder accessed part of its online store, according to an email first reported by KitGuru. The message, quoted by the company, said investigators had identified “unauthorized access to part of the Asus eShop environment.” Asus notified affected customers by email and says it launched an investigation after discovering the activity.

Customer data at risk: contact details and order records

Asus’s investigation found that “certain customer order information, including contact details and order records, may have been accessed.” Those elements, the company warned, could make scam messages — phishing emails, texts, or phone calls — about Asus products or customers’ orders more convincing, because the attacker may possess verifiable purchase details and receipts.

Asus told customers to watch for unexpected messages referencing previous purchases. The company also said it is not currently aware of the compromised information being misused or of any affected customers suffering harm.

Payment information: Asus says cards and bank accounts were not involved

There is at least some reassurance for customers who used payment cards on the eShop: Asus stated that “no payment card, bank account, or other financial information was involved in the breach.” The company further reported that, after discovery, it took steps to contain the incident, introduced additional measures to secure the affected systems, and had “found no evidence of continued unauthorized access.”

December supplier incident involving the Everest ransomware gang

This is not the company’s only recent security headline. In December, Asus confirmed that one of its suppliers had been hacked after the Everest ransomware gang claimed to have taken 1 TB of data from itself, ArcSoft, and Qualcomm. Asus said that haul included some camera source code used in its phones, while maintaining that “its own systems and customer data were untouched” at that time.

What this means for customers, security teams, and threat actors

  • Customers: Asus’s notice specifically warns buyers to monitor for unexpected emails, texts, and calls that reference past orders. The company believes the risk of misuse is low but explicitly flagged the increased plausibility of scams because order evidence may now exist outside Asus systems.
  • Security teams and incident responders at Asus and suppliers: Asus reports it contained the incident, launched an investigation, and added security measures, and it says it “found no evidence of continued unauthorized access.” The Register has requested more detail from Asus about scope, timing, and the avenue of intrusion but “has not yet received a response.”
  • Threat actors: If contact details and order records were removed, attackers could use the data to craft targeted phishing that references specific purchases — an advantage the company acknowledged when warning customers to be vigilant.

Disclosure gaps and the immediate next steps

Asus has not provided several commonly expected details: the company has not said how many customers were affected, when the intrusion began, how long the attacker had access, which countries were impacted, or how the intruder gained entry to the eShop environment. Asus is “yet to comment publicly on the incident,” and there is no mention of the breach on the eShop itself, the Register reports.

For now, Asus’s public messaging centers on containment, an ongoing investigation, and targeted customer warnings. That posture — asserting a low risk to financial information while acknowledging probable exposure of order and contact records — leaves customers with a concrete, narrow action: scrutinize any incoming communications that reference past purchases and treat unexpected requests for information as potentially malicious.

The Register asked Asus for further details and has not yet received a response. Readers can review the original reporting here: https://www.theregister.com/security/2026/09/24/someone-went-shopping-in-asuss-eshop-for-customer-data/5298860