Investigation · Online Store Customer Data

ASUS eShop Data Breach Investigation

Hall Attorneys is evaluating potential claims concerning the ASUS eShop data breach reported on September 23, 2026. In a customer notice reproduced by KitGuru, ASUS says unauthorized access to part of its online store may have exposed contact details and order records. ASUS says payment card, bank account, and other financial information were not involved.

Public report
September 23

2026 · customer notice reported by KitGuru

People affected
Not disclosed

no customer count in the reviewed notice

Reported risk
Phishing

messages and calls using order-related details

Could this be me?

Could my ASUS eShop order be involved?

Start with your own purchase records and any ASUS incident notice. These can help identify the store you used and the information associated with an order.

  1. You ordered directly from an ASUS online store

    Keep your order confirmation, invoice, purchase date, and the store's country or website address. A direct purchase establishes a relationship, not proof of exposure.

  2. You received an incident notification

    Save the original message and its full email headers. Verify it through a known ASUS website or support channel before following links or providing information.

  3. An unexpected message refers to an ASUS order

    Preserve the message, sender details, and date. Familiar order information does not authenticate a sender, and a suspicious message alone does not prove a connection to this incident.

Check your records

Check your own order records

Search your email for the store name, receipts, and notifications. You do not need to obtain leaked data to document a purchase or report a concern.

ASUS eShopASUS orderASUS invoiceASUS notice
  • Record the store country, approximate purchase dates, and when you received any incident notice.
  • Keep original notices, order confirmations, and suspicious communications.
  • Track time, expenses, account changes, or losses associated with suspected misuse.
  • Use a brief description in an initial inquiry; do not send passwords, payment details, or unredacted identity documents.

Answer at a glance

What happened in the September 2026 ASUS eShop breach?

KitGuru reported on September 23, 2026 that ASUS had emailed eShop customers about unauthorized access to part of the store environment. Its report reproduces the company's notice, which matches the notice shown in the social-media report that prompted this investigation. OC3D also reproduced the notice and credited KitGuru.

ASUS described possible access to customer contact details and order records, excluded financial information, and said its investigation was continuing. Its statement that it was unaware of misuse or harm reflects its knowledge at the time of the notice; it does not resolve whether an individual later received a targeted scam or suffered a loss.

ASUS warned that the information could support convincing order-related emails, texts, or calls. The reviewed material does not establish the entry method, attacker identity, customer count, affected regions, or incident dates. It also does not establish a compromise of ASUS hardware, firmware, or every ASUS account.

This is an investigation, not a filed lawsuit by Hall Attorneys. Facts may change as organizations, regulators, courts, or security researchers publish additional information.

  1. Customer warning reported

    KitGuru published the ASUS eShop customer notice. This is a reporting date, not a confirmed date of the unauthorized access or its discovery.

  2. Hall Attorneys opens investigation

    Hall Attorneys is reviewing the reported incident, notice, potential customer impact, and available records. No ASUS lawsuit filing by the firm is announced on this page.

Reported data categories

What information was involved?

The following distinctions come from the ASUS notice reproduced by KitGuru. A complete field list and individual exposure determinations have not been published in the reviewed material.

Important distinction

Do not infer that passwords, Social Security numbers, identity documents, or payment details were exposed from the phrase customer order information. Financial information is expressly excluded by ASUS; the notice does not resolve every other possible field.

Contact details
Potentially accessed, according to ASUS; individual fields are not enumerated in the notice.
Order records
Potentially accessed; the notice does not specify the full purchase history or date range involved.
Financial information
ASUS says payment card, bank account, and other financial information were not involved.
Scope and credentials
The reviewed notice gives no affected-person count or regional list and does not establish password exposure.

Who may want to contact us

Who should review their ASUS records?

A notice recipient or direct eShop customer can help clarify which store, order, or account was involved. Eligibility for any potential claim depends on the facts and applicable law; this page does not establish a class or entitlement to compensation.

People who received and independently verified an ASUS eShop incident notice.

Direct eShop customers with purchase records relevant to the notice.

Customers documenting suspicious order-related communications, unauthorized changes, or resulting expenses.

What to preserve

What records should ASUS customers preserve?

Keep dated originals where possible and a short chronology of what happened. You can describe your concern before sharing sensitive records.

The complete incident notice

Retain the original email, full headers, received date, attachments, and any follow-up from ASUS.

Purchase and account records

Save order confirmations, invoices, the store address or country, and relevant customer-support correspondence.

Suspicious messages and calls

Preserve screenshots, email headers, caller details, and requests for money or credentials without interacting with suspicious links.

Your response and any losses

Keep support tickets, account-change alerts, receipts for expenses, and a dated record of time spent responding to suspected misuse.

Investigation focus

Issues under review

Hall Attorneys is evaluating the facts needed to assess potential claims. These questions are investigative issues, not findings of misconduct:

  1. Which eShop systems, records, regions, and customers were involved?
  2. When did access begin, when was it discovered, and when were customers notified?
  3. What safeguards governed access to customer order records?
  4. What did notices explain about individual exposure and practical protective steps?
  5. Can reported misuse, expenses, or other harm be connected to the incident?

Public records reviewed

Sources for the ASUS eShop incident

Reviewed September 23, 2026. The incident account relies on ASUS's customer notice as reproduced by KitGuru; OC3D cites that same report and is not an independent forensic confirmation. The support and FTC links provide customer guidance, not evidence of breach scope.

KitGuru · ASUS customer notice reproduced in reporting ·

Asus warns customers of eshop data breach

Matthew Wilson's report reproduces the company notice describing the eShop incident, data categories, response, and phishing warning.

Read source: Asus warns customers of eshop data breach

ASUS ·

Official ASUS support

Official starting point for contacting ASUS and locating support for your region. This is not a breach-status lookup tool.

Read source: Official ASUS support

Contact the firm

Did you receive an ASUS eShop breach notice?

Contact Hall Attorneys with the store country, approximate order dates, when you received a notice, and a brief description of any suspicious communications or losses. Do not include passwords, full payment details, or sensitive identity records in an initial message.

Contact Hall Attorneys

Frequently asked questions

ASUS eShop breach FAQ

Did ASUS confirm an eShop data breach in 2026?

In the customer notice reproduced by KitGuru on September 23, 2026, ASUS acknowledged unauthorized access to part of its eShop environment and possible access to contact details and order records. This page attributes those statements to that notice, not to an independent forensic review.

Were payment cards, bank accounts, or passwords exposed?

ASUS says payment card, bank account, and other financial information were not involved. The reviewed notice does not establish password exposure. Contact details and order records are the categories it identifies as potentially accessed.

How many ASUS customers were affected, and in which countries?

The reviewed notice does not disclose an affected-customer count or a complete list of countries and stores. Owning an ASUS product or having an ASUS account does not by itself establish exposure in this eShop incident.

Did the breach happen on September 23, 2026?

September 23, 2026 is the date of the public reporting reviewed here. The notice does not provide the dates of unauthorized access or discovery, so this page does not treat the publication date as the breach date.

Has ASUS reported misuse or continuing unauthorized access?

As of its notice, ASUS said it was unaware of misuse or harm and had found no evidence of continuing unauthorized access. It said its investigation remained ongoing. Those statements do not rule out later phishing attempts or individual losses.

What should I do about an unexpected ASUS order message?

Save the message and verify it through a known ASUS website or support channel. Do not use unexpected links or disclose passwords or verification codes. If you already provided credentials, change them through the official service; if you sent money, contact your payment provider promptly.

Has Hall Attorneys filed an ASUS data breach lawsuit?

This page announces an investigation, not a filed ASUS lawsuit by Hall Attorneys. The firm is evaluating potential claims and welcomes information from customers with relevant notices, purchase records, or documented harm.

Attorney Advertising

Hall Attorneys is not affiliated with ASUS or the publishers cited on this page. This page concerns an investigation, not a filed lawsuit by Hall Attorneys. Sending information does not create an attorney-client relationship. Do not send passwords, monitoring codes, complete financial-account numbers, government identification, or other highly confidential information unless specifically requested through a secure channel.