
ASUS warns eShop customers that intruder may have taken order data
ASUS has told eShop customers that an intruder got into part of its online store and may have accessed contact details and order records. The PC maker said payment card, bank account and other financial data were not involved.
ASUS has warned customers of its eShop that an intruder got into part of the online store and may have helped themselves to contact details and order records. The PC maker disclosed the incident in an email to customers, first reported by KitGuru.
What ASUS says
The company said its investigation identified "unauthorized access to part of the Asus eShop environment," though exactly when that access occurred remains unclear. "Our investigation indicates that certain customer order information, including contact details and order records, may have been accessed," the email said.
ASUS said no payment card, bank account or other financial information was involved in the breach, and that it is not currently aware of the compromised information being misused or of any affected customers suffering harm. After discovering the access, the company contained the incident, launched an investigation and introduced additional measures to secure the affected systems. The investigation continues, but ASUS says it has found no evidence of ongoing unauthorized access.
Questions left unanswered
ASUS has not said how many customers are caught up in the incident, when the intrusion began, how long the attacker had access, which countries are affected, or how the intruder got into the eShop environment. The Register asked ASUS for more details, including how many customers were affected and when and how the intrusion occurred, but has not yet received a response. ASUS has not commented publicly, and there is no mention of the breach on its eShop.
Phishing risk
The details that did escape could give scammers a head start: ASUS warned that they could make phishing emails, texts and phone calls about its products or customers' orders look far more convincing. It told customers to keep an eye out for unexpected messages mentioning previous purchases, though it reckons the risk of actual misuse of the data remains low.
A recent precedent
This is not the PC maker's first recent brush with data thieves. In December, ASUS confirmed that one of its suppliers had been hacked after the Everest ransomware gang claimed to have stolen 1 TB of data from Asus, ArcSoft and Qualcomm. ASUS said the haul included some camera source code used in its phones, but maintained that its own systems and customer data were untouched.
So it is the usual post-breach drill: beware unexpected emails, texts and calls. Except this time, whoever is behind them may have the receipts.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.