British fashion and e-commerce company ASOS has confirmed that a recent data breach was caused by a social engineering , revealing once again how critical the human factor can be in cybersecurity. The attackers managed to trick an employee of the company and obtain login credentials , which they then used to gain access to data hosted on third-party platforms.
How the attack started
According to ASOS, an unauthorized user managed to gain access to an employee's accountby impersonating a trusted contact. In doing so, they convinced the employee to reveal the information required to log into the account.
The incident is a prime example of social engineering, a type of attack in which the cybercriminal does not necessarily have to exploit a technical vulnerability. Instead, they try to manipulate the user into handing over the information needed for the breach.
See also: CrowdStrike links South Korean bank breaches to AI tools and suspect from China
With the stolen credentials, the attackers gained access to information located on specific third-party platforms used by ASOS. This fact highlights another significant risk for modern businesses: the security of external services and partners that are part of their digital infrastructure.

What data was exposed?
The company informed its customers that the incident may have led to the exposure of some key personal and contact information. The latest update states that the data affected includes names, contact information, and some account information that is not considered personal data.
Of particular importance is the fact that ASOS claims that no payment card numbers or other details , nor customer passwords account , were exposed
The company has not yet given a specific number for how many customers were affected. The extent of the breach is therefore still under investigation, which means that the final picture may change as the investigation is completed.
The suspicious notification to customers
The incident became particularly noticeable on October 6, 2026, when ASOS customers received a push notification via the company's app. The message mentioned the theft of customer data and urged staff to contact them via Telegram.
Meanwhile, a cybercriminal group calling itself the “Xuanye Group” claimed to have obtained customer data, claiming it did not have any payment information. The group’s claims do not in themselves constitute proof of the full extent of the attack, but they coincided with ASOS’s official confirmation of the incident.
See also: MonsterCloud case: Charges for hidden ransom payments

ASOS restricts access and launches investigation
After identifying the breach, ASOS restricted access to the affected platforms and launched an investigation involving external cybersecurity experts, relevant law enforcement authorities and regulators.
The company also says it has already implemented additional protection measuresto reduce the likelihood of a similar incident happening again. This move is considered particularly important, as the attack was not based on a simple technical breach of a system, but on the abuse of legitimate credentials.
What customers should watch out for
Although ASOS assures that its website and app remain secure and that no action is required from users, the exposure of names and contact details could pave the way for new attacks.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Cybercriminals could use such information in targeted phishing emails, phone scams or fake messages posing as ASOS communications. For this reason, customers should be extra cautious of any unexpected message asking for passwords, security codes or payment details.
ASOS makes it clear that it does not ask for such information through unsolicited phone calls or messages. The main recommendation is therefore not to share credentials and avoid opening suspicious links, even when the message appears to come from a well-known company.
See also: Cyberattack on Arizona's judicial system: 1.3 million victims

The investigation into the breach remains ongoing and ASOS is expected to release more information if significant new findings emerge. However, the incident is a reminder that data protection depends not only on strong technical systems, but also on the ability of employees and customers to recognize attempts at fraud.
source: www.bleepingcomputer.com
