ASUS warns customers of eShop data breach
ASUS issues warning about eShop data breach
ASUS has reportedly issued a warning to customers about a recent data breach that targeted the ASUS eShop. After the incident, ASUS emailed affected customers to detail what happened. While there has been “unauthorised access” to part of their eShop, only customer order information was accessed. This includes order information, customer contact details, and order records. This breach was first reported by Kitguru.
Thankfully, financial information was not accessed as part of this data breach. ASUS has confirmed that “No payment card, bank account or other financial information was involved”. The breach only affected customer order information.
ASUS claims it has “taken additional security measures” to “secure the affected systems” after learning of the breach. The company’s investigation into the attack is ongoing.
At ASUS, we take the security of personal information seriously. Protecting the information entrusted to us is important and, in keeping with that commitment, we want to let you know about an incident that may have affected some of your information.
ASUS identified unauthorised access to part of the ASUS eShop environment. Our investigation indicates that certain customer order information, including contact details and order records, may have been accessed. We are not currently aware of any misuse of this information or any harm suffered by affected individuals. No payment card, bank account or other financial information was involved.
Upon identifying the issue, ASUS promptly took steps to contain it. We also commenced an investigation and have taken additional measures to secure the affected systems. Our investigation remains ongoing and we have not identified any evidence of ongoing unauthorised access.
– ASUS email to affected customers – via Kitguru
ASUS’ warning also states that attackers could use customer information from the breach in phishing attacks. ASUS’ warning is to help ensure that affected customers are vigilant and are wary of unexpected communication that claims to be from ASUS.
[Customer information] could potentially be used by third parties to send convincing emails, text messages or telephone calls that appear to relate to Asus products, services or orders.
– ASUS email to affected customers – via Kitguru
Thankfully, the impact of this data breach was minimal. That said, ASUS eShop customers should be extra careful. While attackers did not access financial details, the personal details of customers were. If nothing else, these customers should be wary of any communications claiming to be from ASUS.
So far, ASUS has not publicly commented on the data breach. Aside from KitGuru’s report, there are no details about the breach available online.
Did you get an email from ASUS this afternoon? Join the discussion on ASUS emailing customers about an eShop data breach on the OC3D Forums.
