Asus eShop Breached, Customer Data and Order History at Risk of Misuse
Baca dalam 60 detik
- Asus mengonfirmasi kebocoran data pada platform eShop-nya, dengan informasi kontak dan catatan transaksi pelanggan diduga telah diakses pihak tak berwenang.
- Perusahaan tidak mengungkap skala kerugian maupun wilayah terdampak, sementara data yang bocor berpotensi besar dipakai untuk serangan phishing yang menyamar sebagai Asus.
- Pakar keamanan menilai kasus ini menjadi alarm bagi konsumen di Indonesia agar waspada terhadap upaya penipuan yang memanfaatkan data transaksi asli.

Technology company Asus announced that its online store, Asus eShop, suffered a security incident that exposed a number of customer data. The affected information includes contact details and order records, although the company confirmed that no payment or financial data was leaked.
The announcement was delivered via email to customers who had previously transacted on eShop. However, Asus did not specify how many accounts were affected, which countries were impacted, or the duration of the attack. The official statement only mentioned "part of the Asus eShop environment" without further explanation. Because eShop is operated separately by region, this lack of clarity makes it difficult for customers to assess whether they are among the victims.
To date, no public statement has been posted on Asus's official website. Information has only circulated from screenshots of emails received by customers and shared on social media. Asus claims it "immediately took steps" to contain the incident and found no ongoing unauthorized access. An internal investigation is still underway.
"Data leaks like this often become an entry point for highly convincing phishing attacks because attackers can cite genuine order details," said a cybersecurity analyst who wished to remain anonymous.
Asus reminded customers to be cautious of suspicious communications claiming to be from the company. Possible tactics include phone calls, emails, or text messages that include names, addresses, and purchase history as proof of authenticity. Customers are urged not to click links or scan QR codes from unknown sources, and to always access official websites manually through a browser.
In the Indonesian context, this incident highlights the vulnerability of consumer personal data on global e-commerce platforms. Although Asus did not name Indonesia as an affected region, local customers who have shopped on eShop could still be targeted. Digital security awareness in the country remains a work in progress, especially with the rise of online fraud exploiting leaked data from various services.
Cybersecurity experts assess that large technology companies need to be more transparent in communicating incidents like this. Openness about the scale and affected regions would help users take appropriate mitigation steps. On the other hand, consumers are encouraged to enable two-factor authentication (2FA) on all important accounts, and never provide personal information or passwords through unverified communication channels.
Going forward, the Asus case could set a precedent for regulators in Indonesia to strengthen personal data protection rules, particularly regarding the obligation to report incidents within a certain timeframe. Without clear sanctions, multinational companies tend to be slow in announcing breaches. The question is, will customers in Indonesia receive adequate information if they are proven to be among the victims? Only time will tell, but vigilance now is key.



