ASOS links data breach to social engineering attack, credential theft

UK Fashion Retailer ASOS Hit by Social Engineering Attack, Exposing Customer Data

ASOS, a leading online fashion retailer based in the UK, has fallen victim to a sophisticated social engineering attack that has resulted in customer data being compromised. The attackers, who claim to be part of a group called “Xuanye Group,” stole an employee’s login credentials by impersonating a trusted contact and used them to access information on third-party platforms used by ASOS.

According to a security notification shared with BleepingComputer, the hackers gained unauthorized access to an ASOS employee account by tricking the victim into divulging their login credentials. The attackers then used these stolen credentials to access sensitive information on various third-party platforms, including those used for customer data management and analytics. While the company has confirmed that no payment card information or account passwords were accessed, some basic personal information and contact details may have been exposed.

The breach is believed to have occurred in late September 2026, although it wasn’t until October 6th that customers received a push notification through the ASOS app on their mobile devices, warning them of potential customer data theft. The attackers’ tactics are characteristic of a social engineering attack, where hackers manipulate individuals into divulging sensitive information or performing certain actions.

ASOS has assured its customers that its website and app remain completely safe to use, but has warned them to be cautious of unexpected messages or calls claiming to be from the company. In a statement published on its website, ASOS emphasized that it will never ask customers to share passwords, security codes, or payment details through unsolicited messages or calls.

The investigation into the breach is ongoing, with ASOS working closely with external experts, law enforcement, and regulatory authorities to determine the full extent of the damage. The company has promised to provide further updates as more information becomes available. While no official figure has been released on the number of customers affected by this incident, it serves as a stark reminder of the importance of robust security measures and employee awareness in preventing social engineering attacks.

For ASOS customers, the takeaway from this breach is clear: vigilance is key when it comes to protecting your personal information. Be cautious of unexpected messages or calls claiming to be from ASOS, and never share sensitive information through unsolicited channels. By being aware of these tactics and taking steps to protect yourself, you can minimize your risk of falling victim to a similar attack in the future.


Source: Bleeping Computer — 2026-10-08