Asus has confirmed a data breach affecting its eShop, with customer order records and contact details exposed, though the company says payment information was not compromised. The incident was disclosed to affected customers through an email rather than a public statement. Asus has not said how many customers were impacted or which countries and regions had records leaked, citing only that the breach touched part of the Asus eShop environment. Because the eShop is organized by region and country, it remains unclear which locations are involved.

According to the company's message to customers, Asus acted quickly to contain the breach and has found no evidence of continuing access. The company also said an investigation is still underway. It has not provided any information about how long the breach lasted or who might be responsible. No statement has been posted publicly by Asus beyond what recipients of the notification email have shared.

The data involved could allow attackers to impersonate Asus convincingly. A scammer posing as a company representative could cite a customer's name, address and order history to make a fraudulent contact appear legitimate. Asus is warning customers to be cautious about such approaches, which are consistent with targeted phishing. The risk applies to anyone whose information was included in the leaked records.

Customers whose credentials may have been exposed are being told to watch for unexpected emails, phone calls, text messages or online messages that claim to come from Asus. Recipients should not click links or scan QR codes in those messages; instead, they should open the relevant website manually in a browser. Asus also advises against sharing personal information or passwords during phone calls.

The company further cautions against granting remote access to a device unless the customer is certain the person on the other end is genuine support. Enabling two-factor authentication, also known as 2FA or MFA, is recommended so that an attacker cannot reach an account even with a stolen password. That guidance mirrors standard practice for credential leaks, in which stolen passwords are often the first step in an account takeover.

For US customers, the lack of detail about scope and affected regions leaves uncertainty about whether American eShop records are among those exposed. Asus has not identified the affected regions, so customers in the United States and elsewhere have no way to confirm from the company's statements whether their data was involved. The company's email remains the primary notice to those whose records were part of the incident.

Asus has not released a timeline for the investigation or indicated when more information might be available. The company's account to date rests on its email to customers and the confirmation that payment data was not affected. Until Asus provides additional detail, the size, duration and origin of the eShop breach remain unknown.

More cybersecurity news from TechManNews.