Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Data Breaches » Threat Actor Claims 1TB of Data Linked to ASUS is for Sale on Dark Web

Threat Actor Claims 1TB of Data Linked to ASUS is for Sale on Dark Web

Last updated:September 7, 2026
Human Written
  • A threat actor claims they have a 1-tetrabyte database tied to computer hardware and electronic manufacturer ASUS for sale.

  • The listing shows little information on the data itself, the impacted systems, and how the actor claims to have gained access to them.

  • ASUS has not made any statements confirming if it suffered any breach so the authenticity of this claim remains unverified.

Threat Actor Claims 1TB of ASUS Data Is for Sale on Dark Web

A new dark web listing claims that a cybercriminal has a large database allegedly belonging to ASUS. Threat intelligence accounts on X started reporting this on September 6, 2O26, saying the listing puts the database at 1,023.67 GB.

The actor also posted several samples as proof of possession. Those samples have not established that the data came from ASUS systems. The listing gives no clear answer on which ASUS systems or business units may be involved.

But there’s currently no info about what’s actually in the database, or when the supposed access even happened. So right now, there’s just not enough to say this is a real ASUS breach.

What the Threat Actor Claims

The seller claims to hold a large database belonging to ASUS. The size is striking. A 1 TB database could hold a huge amount of data. But size alone tells us little about the risk.

A huge archive may hold backups, duplicate files, logs, old files or other documents that aren’t really important. But sometimes, a much smaller database is what poses greater risks especially if it contains passwords, customer data, source code, or anything else sensitive.

The real question is: are these samples real, and can researchers actually tie them back to ASUS? The public evidence does not yet make that connection.

No Clear Attack Path Has Been Revealed

The claim also lacks basic details about the alleged attack. The listing does not identify a specific ASUS server, service, application, or business unit. It does not explain how the seller says it gained access.

It is also unclear whether the data is new. Threat actors sometimes recycle old leaks and offer them as fresh material. They can also combine data from several sources and attach a major company name to the package.

Researchers need to compare the samples with known ASUS data before drawing conclusions.

In September 2026, a threat actor claimed to sell a 1TB database allegedly stolen from healthcare technology firm Omnicell for about $31,500, including a 7.5GB sample. However, the claim remains unverified, with no independent confirmation that the data came from Omnicell’s systems.

ASUS Has Faced a Separate Data Exposure

The new claim is notable because ASUS confirmed a separate supplier incident in December 2O25. ASUS said a supplier had been hacked. The company said the incident affected some camera source code for ASUS phones.

ASUS also said the incident did not affect its products, internal company systems, or user privacy. The earlier case followed claims that the Everest ransomware group had stolen about 1 TB of data tied to ASUS, ArcSoft, and Qualcomm. That incident shows why the source of alleged stolen data matters.

Data linked to ASUS does not always mean attackers broke into ASUS’s own network. A supplier can hold company information and become a separate point of exposure.

The latest listing could involve ASUS itself, a supplier, or another source. There is not enough evidence to say which one.

The Samples Will Matter Most

If researchers can verify the posted samples, the story could change quickly. They would need to show that the files are real ASUS data. They would also need to check if the data is new or appeared in an earlier incident.

If the samples match data from the 2O25 supplier incident, the latest listing could involve old material. If the files contain previously unseen internal records, the claim would become much more serious.

The type of data would also shape the impact. Customer records could create privacy risks. Internal credentials could create security risks. Source code could expose company technology. But none of those outcomes has been established yet.

No Confirmation from ASUS Yet

There are no public ASUS statements about this particular claim from September 2O26. This does not mean that the claim is untrue. It means there is not enough verified evidence to report it as a confirmed breach.

For ASUS customers, there is no reason to assume their personal information was exposed based on this listing alone. Users should still keep ASUS software and firmware updated and watch for unusual emails or messages.

Security teams have a reason to monitor the claim. If researchers verify the samples, they can figure out where the data came from, how old it is, and what’s actually inside the supposed database.

Currently, all we have is the actor’s claims of having a large trove of ASUS data they’re trying to sell. But as of yet, nobody has confirmed if a real breach actually happened.

Share this article

About the Author

Memchick E

Memchick E

Digital Privacy Journalist

Memchick is a digital privacy journalist who investigates how technology and policy impact personal freedom. Her work explores surveillance capitalism, encryption laws, and the real-world consequences of data leaks. She is driven by a mission to demystify digital rights and empower readers with the knowledge to protect their anonymity online.

View all posts by Memchick E >
Comments (0)

No comments.