New Delhi: PC maker ASUS has informed customers about a data breach involving part of its ASUS eShop environment, warning that certain customer information, including contact details and order records, may have been accessed by an unauthorised party.
The company has sent emails to registered ASUS eShop customers about the incident. According to the communication cited by India Today, ASUS identified unauthorised access to part of its e-commerce environment and found that some customer order information could have been exposed.
ASUS has said that payment information such as bank account details was not affected. The company also said it is not currently aware of any misuse of the potentially affected information or any harm suffered by customers.
What customer information may be at risk?
The company has indicated that the potentially affected information includes contact details and order records linked to customers using ASUS eShop.
The breach does not appear to involve customers’ payment information, according to ASUS’s communication. The company specifically said bank account details were not part of the affected information.
However, contact and purchase-related information can still be useful to fraudsters. ASUS has warned that third parties could potentially use the information to send convincing messages or make calls that appear to be connected to ASUS products, services or previous orders.
This creates a potential risk of phishing and impersonation attempts, particularly because an attacker possessing genuine order-related information could make fraudulent communications appear more credible.
ASUS says payment information was not affected
One of the key points in ASUS’s notification is that payment information was not included in the breach.
The company said customers’ bank account details were not affected and that it has no current knowledge of any misuse of the information.
However, ASUS has not said that the investigation is complete. The company is continuing to examine the incident and determine what happened and how the unauthorised access occurred.
ASUS also said there was no evidence of continuing unauthorised access at the time of its customer communication.
Company has contained the affected systems
ASUS said it took steps to contain the incident after identifying the unauthorised access.
The company has secured the affected systems, but its investigation has not yet identified the cause of the breach. ASUS said its investigation remains ongoing and that it has not found evidence of continued unauthorised access.
The company has not publicly disclosed how many customers may have been affected.
India Today reported that it contacted ASUS for a response and that the company had not provided additional details at the time of publication.
Customers warned about phishing attempts
ASUS has specifically warned customers that potentially exposed information could be used by third parties to carry out fraudulent communications.
These could include emails, text messages or telephone calls that appear to relate to an ASUS product, service or order.
For example, a fraudulent message could refer to a genuine ASUS purchase and then ask the customer to click a link, provide additional personal information or make a payment. Such messages can appear more convincing when they contain details associated with a customer’s actual transaction.
Customers should therefore be cautious about unexpected messages claiming to be from ASUS, even if the communication contains apparently accurate information about a previous purchase.
What ASUS customers should do
Customers who receive emails or messages claiming to be from ASUS should carefully verify the sender and avoid clicking on suspicious links.
They should also avoid sharing passwords, one-time passwords, card details or other sensitive information in response to unsolicited communications.
ASUS has an official customer support channel and has separately warned users about unofficial websites, platforms, emails and messaging channels impersonating the company. The company advises users to use its official websites and support channels when checking information about products or services.
Customers should also be particularly cautious if a caller claims to know their ASUS order details and then requests additional information or payment.
ASUS has faced security incidents before
The latest incident is not the first cybersecurity issue associated with ASUS.
In December 2025, ASUS disclosed a separate incident involving one of its suppliers after the Everest ransomware group claimed to have stolen more than 1 TB of data from the company.
ASUS said at the time that the incident involved some camera source code for its phones and did not affect its products or user privacy, according to the India Today report.
The latest incident, however, concerns unauthorised access to part of the ASUS eShop environment and potentially affected customer order information.
Investigation is still underway
ASUS has not yet disclosed the full scope of the latest incident or identified the cause of the unauthorised access.
The company has said that affected systems have been secured and that there is currently no evidence of ongoing unauthorised access. It also said it is not aware of any misuse of the potentially affected information or harm to customers at this stage.
For customers, the main concern at present is the possibility of targeted phishing or impersonation attempts using contact and order information.
As the investigation continues, ASUS may provide further information about the number of affected users, the cause of the incident and any additional steps customers need to take.
