A shopper uses a laptop as personal details flow toward email and phone icons beside a shield securing payment cards.
ASUS has told customers of its online store, the ASUS eShop, that an intruder got into part of the store's systems. The company says contact details and order records may have been accessed, and that payment card, bank account and other financial information was not involved. The warning went out by email and was first made public on September 23, 2026. There's no emergency here and no card to cancel. The real risk is quieter. Someone may now know your name, how to reach you and what you bought from ASUS, which is exactly what makes a scam email or phone call believable.

ASUS hasn't given the numbers people most want. The company has not said how many customers are affected, which countries or regional stores are involved, when the intrusion began, how long it lasted, or how the attacker got in. For now, the practical response is careful behavior, not account-by-account cleanup.

ASUS eShop breach notice: what the company actually confirmed​

The disclosure came in an email that KitGuru reproduced on September 23. In it, ASUS said it had identified unauthorised access to part of the ASUS eShop environment. Our investigation indicates that certain customer order information, including contact details and order records, may have been accessed. OC3D, Cyber Daily and The Register all ran the story afterward. Each credits KitGuru for the notice, so they amount to one primary document reported several times, not independent confirmation. The text matches word for word across all of them.

The words "may have been accessed" are doing real work. Some headlines, including The Register's, describe the records as accessed outright. ASUS's own wording is more careful: its investigation indicates possible access to certain order information. That doesn't mean every eShop customer lost every field on file. ASUS also hasn't listed which fields "contact details" and "order records" include. KitGuru's reading is that recent Asus customers may have their names and contact details leaked, which could lead to an uptick phishing / scam attempts. That's the outlet's interpretation, not something ASUS listed.

On financial data, ASUS gave a flat denial: "No payment card, bank account or other financial information was involved." The notice doesn't mention passwords or account credentials at all. So nothing ASUS has published says eShop logins were exposed, and nothing says they weren't. That gap is the one detail that could change what customers should do.

Containment claims in the ASUS eShop incident rest on the company's word​

ASUS described a standard response. According to the notice, upon identifying the issue, ASUS promptly took steps to contain it. We also commenced an investigation and have taken additional measures to secure the affected systems. Our investigation remains ongoing and we have not identified any evidence of ongoing unauthorised access. The company also said it is not currently aware of any misuse of this information or any harm suffered by affected individuals.

All of these statements come from ASUS, and none has been independently verified. They describe what the company knew when it sent the email. "Not currently aware of any misuse" is a snapshot in time. Stolen contact and order data usually gets used in phishing campaigns weeks or months later, not the day it's taken.

The timeline is the biggest hole. The notice gives no date for the intrusion or its discovery. September 23 is only the day the warning became public, not the day of the breach. The Register says it asked ASUS how many customers were affected and when and how the intrusion happened, and had no answer by publication. It also reported that ASUS had made no public statement and that the eShop itself carried no mention of the breach. Cyber Daily, an Australian security outlet, says it has also reached out to Asus for further comment. Nobody has yet reported a response.

Why order records make eShop phishing more convincing​

ASUS says the email was sent as a precaution, because the information involved "could potentially be used by third parties to send convincing emails, text messages or telephone calls that appear to relate to Asus products, services or orders". The company believes the risk is limited. The Register reports that ASUS told customers to watch for unexpected messages that mention previous purchases.

This is how the attack would likely work. A generic "your package is delayed" text is easy to ignore. A message that names the exact laptop or router you ordered, gets your delivery address right and sounds like an order confirmation is much harder to dismiss. Details that normally prove a message is genuine become a disguise. A scammer doesn't need your card number if they can talk you into typing it into a fake "refund" or "delivery fee" page.

The store's own rules show why the data is so useful. The US ASUS eShop terms say that to keep customers informed about order status, returns and refunds, the store requires contact information, "including email address and mobile number." So a typical eShop record probably holds both an email address and a phone number. That fits ASUS's warning, which covers email, texts and phone calls. The terms describe what the store collects in general, not what was taken in this incident.

Who is in scope for the ASUS eShop breach, and who isn't​

Only the ASUS eShop is involved: the company's direct online store. Nothing reported points to ASUS hardware, firmware, driver downloads or the MyASUS app, and nothing touches products bought from other retailers. Owning an ASUS laptop you bought from a third-party store doesn't put you in this incident. Having bought directly from an ASUS eShop is the relevant factor. Even then, ASUS hasn't said whether all eShop customers are affected or only some. The notice went to registered Asus eshop customers, and ASUS hasn't said which regional stores were involved.

Business buyers are affected too. UK security consultancy CyPro notes that the affected group could include individual consumers, sole traders and businesses that have used the store to buy laptops, desktop computers, components, networking equipment or accessories. Small firms that buy hardware directly from ASUS may find their procurement staff getting order-themed scams. The ASUS order details would make those messages look like normal supplier correspondence.

This isn't ASUS's first recent brush with data thieves. Late last year the company confirmed that a supplier had been breached, after the Everest ransomware gang claimed to have taken 1 TB of data from ASUS, ArcSoft and Qualcomm. At the time ASUS said its own systems and customer data were untouched. Cyber Daily reports that the two incidents are not thought to be related. Nothing public links the supplier breach to how the eShop was entered, and nothing public explains how the eShop was entered at all.

What this means for you​

If you've bought directly from an ASUS eShop, treat any unexpected ASUS-branded message as suspect for the next few months, however accurate its details look. You don't need to change a card, since ASUS says no financial data was involved. Password advice depends on what you already do. The notice says nothing about credentials, so changing your eShop password costs little. It matters most if you reused that password anywhere else, and the reason is good habit, not any confirmed exposure.

For IT admins and helpdesk staff, the job is awareness. If your organization buys ASUS hardware through the eShop, let procurement and finance know that emails, texts or calls quoting real ASUS order details may be fake. That's especially true of anything asking for payment, a changed delivery address, a "refund verification" or a login.

  • ASUS says contact details and order records from part of its eShop "may have been accessed," and that payment card, bank account and other financial information was not involved.
  • ASUS has not disclosed how many customers are affected, which regions or stores are involved, when the intrusion happened, or whether passwords were exposed.
  • If a message mentions your past ASUS purchase, don't use its links or phone numbers. Check the order by going to ASUS's website or support channel yourself.
  • Never give passwords, one-time verification codes or payment details to unsolicited contact, even when the caller or sender knows your order history.
  • Keep ASUS's original notice and any suspicious messages, in case ASUS or regulators publish more details later.
  • Owning an ASUS product bought from another retailer doesn't put you in this incident. Direct eShop purchases are what matter.

ASUS's disclosure covers a small set of data, and the company describes the risk as limited. That may well be right as far as financial fraud goes. But the data it confirms may be exposed is exactly what makes impersonation work, and ASUS has yet to say how many people are affected or where. What matters next is whether ASUS publishes a customer count, a timeline or regional details, whether in answer to press questions or through breach notifications to regulators. Until then, eShop customers should be wary of any message that seems to know what they bought.