ASOS US Sales LLC Reports Data Breach to Oregon Regulators
ASOS US Sales LLC filed a data breach report with Oregon authorities on September 9, 2026, regarding an incident on July 28, 2026. The exposed data includes Full Name, Email Address, Mailing Address, Password or Credential Hash, Purchase and Order History, Payment Card Information, Phone Number, and Customer Account Preferences. Individuals affected by this breach should monitor for suspicious activity, as these details could be used for identity-related fraud or unauthorized account access.
- State
- Oregon
- Breach date
- July 28, 2026
- Reported
- September 9, 2026
What may have been exposed
- Full Name
- Email Address
- Mailing Address
- Password or Credential Hash
- Purchase and Order History
- Payment Card Information
- Phone Number
- Customer Account Preferences
ASOS US Sales LLC, an online apparel and lifestyle retailer, reported a data security incident to Oregon regulators on September 9, 2026. The company stated the incident occurred on July 28, 2026. Public filings indicate that the nature of the breach is currently unspecified, and the investigation status is listed as monitoring.
According to the official report, the data categories involved in this breach include Full Name, Email Address, Mailing Address, Password or Credential Hash, Purchase and Order History, Payment Card Information, Phone Number, and Customer Account Preferences. This information is typically used for managing customer accounts and processing online purchases through the platform.
Exposure of such personal information can create risks for affected individuals. Compromised email addresses and full names might be used in targeted phishing attempts. If credential hashes are exposed, unauthorized parties could attempt to gain access to online accounts, not just with ASOS but potentially on other websites where users reuse passwords.
Individuals who receive notification regarding this breach should consider updating their passwords for ASOS and any other online accounts where the same password was used. It is also recommended to enable multi-factor authentication (MFA) on all available online services. Regularly reviewing statements from financial institutions and credit reports for any unauthorized activity is an important protective measure.
Source: Oregon Attorney General filing