ASOS just told its US customers that nobody broke into ASOS. Someone logged into their accounts with passwords stolen from somewhere else - and if you reuse passwords, that “somewhere else” is every site you have ever joined.
What Happened at ASOS?
The timeline, in order:
- July 28: ASOS noticed unusual activity on customer accounts.
- July 29: ASOS confirmed the pattern. Accounts were being accessed with login credentials that came from outside ASOS. It blocked the affected accounts and forced password resets.
- July 30: ASOS emailed customers telling them to create new passwords.
- August 21: ASOS sent written notices and filed with the California Attorney General.
About 138,828 people are in the affected population, according to an investigation notice published by a law firm tracking the case. ASOS itself has not put a number on it. The company says the affected accounts were locked on July 29, suspicious orders were stopped where they were found, and no further unauthorized activity has been detected since.
Notice what is missing from that story: a break-in. ASOS does not claim its own systems were breached. It says the credentials came from outside.
What Was Actually Taken?
The notices list what may have been visible inside those accounts:
- Names
- Email addresses
- Delivery and billing addresses
- Telephone numbers
- Dates of birth
- Details of linked social media accounts - not the passwords to those accounts
- Redacted payment card information: the cardholder name, the last four digits, and the expiration date
No full card numbers. No CVV codes. No ASOS password database.
That last part changes the response, so it is worth reading twice. This is not a “freeze your credit and order new cards” breach. It is a “your passwords are the problem” breach. The data inside those accounts - address, phone, date of birth, card fragments - is ammunition for phishing. A thief who knows your name, your address, and the last four digits of your card can write a very convincing fake ASOS email. But the way in was a password, and that is the part you can actually fix.
What Is Credential Stuffing?
Credential stuffing is when attackers take username-and-password pairs stolen from one site and try them against hundreds of other sites automatically. It works because people reuse passwords.
Here is the mechanism in plain terms. Every data breach that ever leaked usernames and passwords produced a list. Those lists get sold and traded in bulk, then merged into giant files called combo lists: millions of pairs, all real, all stolen from somewhere. Attackers run a combo list against Amazon, PayPal, ASOS, and thousands of other sites at once, software doing the trying. Most attempts fail. The ones that succeed succeed because somebody reused a password.
ASOS did not hand over a database. ASOS was tested against a list of keys, and for 138,828 of its accounts, a key fit.
That is the uncomfortable part of this story. The retailer’s login system was not the weak point. The weak point was every other website you have ever joined, plus the habit of using the same password on all of them.
Why Is Password Reuse the Real Problem?
Because every breach dump feeds the next attack. The password you used for a forum in 2019 is being tried against your bank right now. Not by a person - by software, millions of times a day, against thousands of sites. You never get a vote on whether your old passwords circulate. You only get a vote on whether they still work.
One reused password means every site you have ever joined is a potential door into every account you have. The ASOS customer with a unique ASOS password got a notice and a reset, and that was the whole story. The customer who used their Netflix password at ASOS is now wondering which other accounts share it - and the attacker already knows the answer, because the password came off a list that says exactly which site it originally belonged to.
You are not one breach away from losing your accounts. You are one reused password away.
The Fix: Five Steps This Week
If you have an ASOS account, or if you have ever reused a password anywhere, this list is this week’s homework. Each step is small. Together they close the loop.
Step 1: Find Every Account That Shares a Password
Start with the password you used at ASOS, or whichever password you actually reuse the most. Then make a list of every site that uses it.
Your browser has already done half the work. Open its saved-passwords list - Chrome, Edge, and Safari all keep one - and look for repeats. Any password that appears next to more than one site is a reused password, and that is the list you need. You will not remember all of them from memory. That is the point, and the reason Step 4 exists.
Step 2: Change Them, Starting With Email and Banking
Change ASOS first, then work down the list. The order matters. Email is the master key: anyone inside your email can reset the password to almost everything else you own. So email first, then banking and payment apps, then everything else. Each new password should be different from the old one and different from every other site.
While you are at it, glance at your card statements for the next month or two. The fragments in those accounts plus your address are enough for a convincing fraud attempt, and catching one early is cheap.
Step 3: Turn On Two-Factor Authentication
Even a unique password can be stolen once. Two-factor authentication means a password alone is not enough: the site also asks for a code from an authenticator app or a text message. Turn it on everywhere it is offered, starting with email and banking. If the site lets you choose between an app and text codes, pick the app. It does not depend on your phone number, and it is the harder target.
Step 4: Start a Password Manager This Week
This is the step that ends the cycle for good. A password manager keeps every password in one encrypted vault, locked by a single master password. It generates a random password for each site, stores it, and fills it in when you log in. You memorize one password instead of fifty, and no two sites ever share one again.
The realistic math: if you are not using a password manager, you do not have unique passwords everywhere, because it is not humanly possible to remember them. The manager is not an extra chore. It is the only practical way to make Step 2 permanent.
You do not need to do it all in one sitting. Set it up, then change passwords as you log into each site over the next few weeks. The important part is starting.
Step 5: Check Have I Been Pwned
Have I Been Pwned is a free site run by a security researcher that collects data from known breaches. Type your email address, and it tells you which breaches your address appears in. It also has a password search: type a password, and it tells you whether that exact password is in any known dump. Both are safe to use.
Two things to know before you look. First, seeing your email listed is normal - most people with an email address older than a few years are in some dump. It is not itself a reason to panic. Second, check what the entry says: if the breach involved passwords, those passwords are circulating, and anywhere you reused them needs changing. That is the check ASOS customers wish they had run in July.
What Not to Do
The follow-up scams are already running. Three rules:
Do not click links in breach emails. Real notices tell you to log in on the real website. Fake ones want you to click. Type ASOS’s address yourself and log in there.
Do not hand over anything to someone who contacts you. No company, no bank, no “security team” will ever ask for your password, a screen-sharing session, or gift cards to fix a breach. That sentence is the whole scam test. If someone calls or messages and asks for any of those, hang up.
Expect copycat messages. Scammers will send fake “ASOS breach update” emails for months. ASOS’s real help runs through the get-in-touch page on its official site, not through links in emails.
This Is the Prevention Article
There are two halves to this subject, and this site covers both. A Company You Bought From Got Hacked - Now What? is the response half: what to do the day a company tells you it leaked your data, with the three-rung ladder for reading a breach notice. This article is the prevention half: what to do before the notice arrives. ASOS is the exhibit where the two meet - a company that was not broken into, whose customers still got notices, because of passwords reused from somewhere else.
For the wider view of where home security actually starts - what a router can and cannot protect - see the network security guide.
The Bottom Line
The ASOS notices are dated August 21, 2026. The accounts were accessed July 28-29. By the time you read this, the same lists are being tested against your other accounts right now.
You cannot un-leak a password. You can make it useless. Change what you reused, turn on two-factor authentication, start a password manager this week, and check Have I Been Pwned. Do that, and the next breach notice in your inbox will be somebody else’s problem.
You are one breach away - but only if your password is still the one from somewhere else.