ASUS disclosed unauthorized access to part of its ASUS eShop environment, potentially exposing customer contact details and order records. The company said payment-card, bank-account, and other financial information were not involved, and it has found no evidence of continuing unauthorized access or misuse of the accessed data.
ASUS said it contained the incident, launched an investigation, and added security measures, but did not disclose the intrusion method, duration, affected regions, number of customers, or suspected actor. Customers were warned that purchase-related data could enable more convincing ASUS-branded phishing emails, SMS messages, phone calls, and online-message impersonation attempts.

See attribution, scope, and your downstream exposure.
1 event from the most recent confirmed update back to the earliest known activity.
ASUS disclosed unauthorized access to part of its eShop environment that may have exposed customer contact details and order records. The company said payment-card, bank-account, and other financial information was not involved, contained the incident, and found no evidence of continuing unauthorized access while its investigation continued.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
tomshardware.com
Open sourcetheregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.