HomeYoutubeASOS: Social engineering attack behind data leak

ASOS: Social engineering attack behind data leak

British fashion and e-commerce company ASOS has confirmed that a recent data breach was caused by a social engineering , revealing once again how critical the human factor can be in cybersecurity. The attackers managed to trick an employee of the company and obtain login credentials , which they then used to gain access to data hosted on third-party platforms.

How the attack started

According to ASOS, an unauthorized user managed to gain access to an employee's accountby impersonating a trusted contact. In doing so, they convinced the employee to reveal the information required to log into the account.

The incident is a prime example of social engineering, a type of attack in which the cybercriminal does not necessarily have to exploit a technical vulnerability. Instead, they try to manipulate the user into handing over the information needed for the breach.

See also: CrowdStrike links South Korean bank breaches to AI tools and suspect from China

With the stolen credentials, the attackers gained access to information located on specific third-party platforms used by ASOS. This fact highlights another significant risk for modern businesses: the security of external services and partners that are part of their digital infrastructure.

ASOS: Social engineering attack behind data leak

What data was exposed?

The company informed its customers that the incident may have led to the exposure of some key personal and contact information. The latest update states that the data affected includes names, contact information, and some account information that is not considered personal data.

Of particular importance is the fact that ASOS claims that no payment card numbers or other details , nor customer passwords account , were exposed

The company has not yet given a specific number for how many customers were affected. The extent of the breach is therefore still under investigation, which means that the final picture may change as the investigation is completed.

The suspicious notification to customers

The incident became particularly noticeable on October 6, 2026, when ASOS customers received a push notification via the company's app. The message mentioned the theft of customer data and urged staff to contact them via Telegram.

Meanwhile, a cybercriminal group calling itself the “Xuanye Group” claimed to have obtained customer data, claiming it did not have any payment information. The group’s claims do not in themselves constitute proof of the full extent of the attack, but they coincided with ASOS’s official confirmation of the incident.

See also: MonsterCloud case: Charges for hidden ransom payments

ASOS: Social engineering attack behind data leak

ASOS restricts access and launches investigation

After identifying the breach, ASOS restricted access to the affected platforms and launched an investigation involving external cybersecurity experts, relevant law enforcement authorities and regulators.

The company also says it has already implemented additional protection measuresto reduce the likelihood of a similar incident happening again. This move is considered particularly important, as the attack was not based on a simple technical breach of a system, but on the abuse of legitimate credentials.

What customers should watch out for

Although ASOS assures that its website and app remain secure and that no action is required from users, the exposure of names and contact details could pave the way for new attacks.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Cybercriminals could use such information in targeted phishing emails, phone scams or fake messages posing as ASOS communications. For this reason, customers should be extra cautious of any unexpected message asking for passwords, security codes or payment details.

ASOS makes it clear that it does not ask for such information through unsolicited phone calls or messages. The main recommendation is therefore not to share credentials and avoid opening suspicious links, even when the message appears to come from a well-known company.

See also: Cyberattack on Arizona's judicial system: 1.3 million victims

ASOS: Social engineering attack behind data leak

The investigation into the breach remains ongoing and ASOS is expected to release more information if significant new findings emerge. However, the incident is a reminder that data protection depends not only on strong technical systems, but also on the ability of employees and customers to recognize attempts at fraud.

source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS