ASUS said it identified “unauthorized access to part of the Asus eShop environment,” according to an email to customers first reported by KitGuru. The company's investigation indicates “certain customer order information, including contact details and order records, may have been accessed.”
The company moved to reassure customers that no payment card, bank account, or other financial information was involved in the breach, and said it is not currently aware of the compromised information being misused or of affected customers coming to harm. ASUS said it took steps to contain the incident after discovering the unauthorized access, launched an investigation, and introduced additional measures to secure the affected systems. That investigation remains ongoing, with the company saying it has found no evidence of continued unauthorized access.
The disclosure leaves several questions unanswered: ASUS has not said how many customers are affected, when the intrusion began, how long the attacker had access, which countries are involved, or how the intruder gained entry. The company has not commented publicly on the incident and has not mentioned the breach on its eShop. The Register asked ASUS for further details but has not yet received a response.
ASUS warned that the exposed details could give scammers enough to make phishing emails, texts, and phone calls about its products or customers' orders look more convincing, and advised customers to watch for unexpected messages referencing previous purchases, while assessing the overall risk of misuse as low.
The incident follows a December breach in which ASUS confirmed one of its suppliers had been hacked after the Everest ransomware gang claimed to have stolen 1 TB of data from ASUS, ArcSoft, and Qualcomm. ASUS said at the time that the haul included camera source code used in its phones, but maintained that its own systems and customer data were untouched.