Someone went shopping in ASUS's eShop – for customer data
Asus says an intruder accessed eShop customer contact details and order records; payment data was not involved.
Asus emailed eShop customers, in a notice first reported by KitGuru, warning of unauthorized access to part of its online store. The company said contact details and order records may have been accessed, while payment card, bank account, and other financial data were not involved. Asus has not disclosed the customer count, countries, start date, or intrusion method, and said it is not aware of misuse or continued access. It warned the stolen order context could make phishing about products or purchases more convincing.
- Intruder accessed part of the Asus eShop environment.
- Contact details and order records may have been exposed.
- Payment cards and bank data were not involved.
- Scale, timing, countries, and entry method were not disclosed.
- Asus warns the data could sharpen order-themed phishing.
Full article460 words · extracted from theregister.com · click to collapse
security
Contact details and order records accessed, but PC maker is keeping schtum on how many customers are affected
Asus has warned eShop customers that an intruder got into part of its online store and may have helped themselves to contact details and order records.
The PC maker disclosed the incident in an email sent to customers, first reported by KitGuru, in which it said had identified "unauthorized access to part of the Asus eShop environment," although exactly when that access occurred remains unclear.
"Our investigation indicates that certain customer order information, including contact details and order records, may have been accessed," the company said.
REG AD
There is at least some good news for anyone who has handed Asus their card details. The company said no payment card, bank account, or other financial information was involved in the breach.
REG AD
Asus also said it isn't currently aware of the compromised information being misused or of any affected customers suffering harm.
The company said it took steps to contain the incident after discovering the unauthorized access, launched an investigation, and introduced additional measures to secure the affected systems. That investigation remains ongoing, but Asus said it had found no evidence of continued unauthorized access.
What Asus hasn't said is how many customers are caught up in the mess, when the intrusion began, how long the attacker had access, which countries are affected, or how whoever was behind the break-in managed to get into the eShop environment in the first place.
The details that did escape, however, could give scammers a decent head start. Asus warned that the stolen details could give scammers enough to make phishing emails, texts, and phone calls about its products or customers' orders look rather more convincing.
Asus told customers to keep an eye out for unexpected messages mentioning previous purchases, though it reckons the risk of anyone actually misusing the data remains low.
This isn't the PC maker's first recent brush with data thieves. In December, Asus confirmed that one of its suppliers had been hacked after the Everest ransomware gang claimed to have pinched 1 TB of data from itself, ArcSoft, and Qualcomm. The company said the haul included some camera source code used in its phones, but maintained that its own systems and customer data were untouched.
The Register asked Asus for more details about the latest breach, including how many customers were affected and when and how the intrusion occurred, but has not yet received a response. Asus is yet to comment publicly on the incident, and there is no mention of the breach on its eShop.
So it's the usual post-breach drill: beware unexpected emails, texts, and calls. Except this time, whoever's behind them may have the receipts. ®