Asus tells eShop shoppers an intruder reached their order records

Asus says an intruder reached part of its eShop and may have taken customer contact details and order records.

CSBadmin
2 Min Read

An intruder reached the Asus eShop, and the PC maker has begun emailing shoppers to tell them so. KitGuru was first to report the customer email, which describes “unauthorized access to part of the Asus eShop environment.”

Asus says its internal review found that “certain customer order information, including contact details and order records, may have been accessed,” wording broad enough to cover much of what a shopper’s account holds, though the company stresses that no payment card, bank account or other financial information was involved.

Asus says it moved to contain the incident, opened an investigation, added safeguards, and has found no sign of continued access. It also says it knows of no misuse of the data so far, and of no customer who has come to harm.

Five questions remain unanswered: how the intruder got into the eShop, which countries the affected shoppers live in, how long the access lasted, when it first began, and how many customers are caught up in total.

Order records are the raw material that makes a fake message land, so Asus is telling shoppers to treat any unexpected call, text or email about a previous order as suspect. It still rates the odds of the data being misused as low.

There is precedent: last December, after the Everest ransomware gang claimed a haul of 1 TB that included camera source code used in Asus phones, the company confirmed one of its suppliers had been hacked, while maintaining that its own systems and customer data came through untouched.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.