Computers

ASOS Blames Social Engineering Attack for Data Breach

ASOS says hackers used stolen employee credentials to access third-party platforms, exposing names and contact details.

ASOS has confirmed that a recent data breach was caused by a social engineering attack in which hackers stole an employee's login credentials. The stolen credentials were then used to access information on third-party platforms used by the company, according to bleepingcomputer.com.

ASOS said it locked down the affected platforms and launched an investigation with external experts, law enforcement, and regulatory authorities. The exposed data included full names, contact details, and certain non-personal account-related information.

The company said hackers did not access payment card information or account passwords. ASOS added that its investigation is still underway.

Earlier claims

On October 6, 2026, ASOS customers received a push notification through the ASOS app alleging customer data theft and urging staff to engage on Telegram. A threat actor calling themselves 'Xuanye Group' claimed to have stolen customer data but not payment information. ASOS later confirmed via a statement on its website that it had suffered a data breach that may have exposed some 'basic' personal information and contact details.

Quick answers

What caused the ASOS data breach?

ASOS confirmed the breach was caused by a social engineering attack in which hackers stole an employee's login credentials.

Was payment card information stolen in the ASOS breach?

No, ASOS said hackers did not access payment card information or account passwords.

What data was exposed in the ASOS breach?

Exposed data included full names, contact details, and certain non-personal account-related information.

Source