ASOS plc
bd_a69235bbeaa283af · schema v1 · pii pii-v2
Full breach record for ASOS plc →ASOS US Sales LLC detected unusual activity on July 28, 2026, and confirmed on July 29, 2026, that an unauthorized third party accessed customer accounts using login credentials obtained from an external source. Affected data included names, email addresses, delivery/billing addresses, phone numbers, redacted payment card details, social media account details, and dates of birth. The company blocked affected accounts, enforced password resets, and canceled suspicious transactions. No malware or ransomware was involved.
J jump to incidentP pin to compareR raw source
Incident timeline
Jul 28, 2026
Begins
Jul 28, 2026
Discovered
Aug 21, 2026
Filed
vs. sector median
5 wks faster
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Washington State AGbd_9d442ecb9bdbc65c2026-08-21Verified
- Vermont State AGbd_b101cf058c931fad2026-08-21Verified
- Texas State AGbd_b9ac20a6aaa107fe2026-08-21Candidate
Filing propagation · 4 filings · 4 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.