Breaches

ASOS Confirms Data Breach Stemmed From Social Engineering Attack on Employee

The retailer says an attacker impersonated a trusted contact to steal employee login credentials, then accessed information on third-party platforms. Customer names and contact details were exposed — but not passwords or payment data. This is distinct from an earlier August breach.

Greater London House in Camden Town, London — ASOS's headquarters.
Greater London House in Camden Town, London — ASOS’s headquarters.

Photo: Lobster1, CC BY-SA 3.0, via Wikimedia Commons

ASOS has confirmed its October data breach was caused by a social engineering attack: “We discovered that an unauthorised party gained access to an ASOS employee account by impersonating a trusted contact to obtain log in credentials.” The credentials were then used to access information on certain third-party platforms used by ASOS, the company said in a security notification shared with BleepingComputer on Oct. 8.

Exposed data includes full names and contact details, plus certain non-personal account-related information. ASOS says no payment-card information or account passwords were accessed. A BBC investigation found the compromised data includes names, addresses, phone numbers, emails, search data, and customer numbers; the hackers shared a sample with the BBC on Oct. 7.

The incident began publicly on Oct. 6, when customers received push notifications through the ASOS app claiming data theft and urging staff to engage on Telegram. The threat actor calls itself the “Xuanye Group” (also rendered Xuanyewen).

Greater London House in Camden, London, home to ASOS's head office.
Greater London House in Camden, London, home to ASOS’s head office.

Photo: Stephen Craven, CC BY-SA 2.0, via Wikimedia Commons

What we know

  • The attack vector: an attacker impersonated a trusted contact to steal an ASOS employee’s login credentials (per ASOS’s Oct. 8 security notification).
  • Exposed: full names and contact details, plus certain non-personal account-related information. Not exposed: payment-card information or account passwords (per ASOS).
  • ASOS says its website and app were not affected and remain safe; it locked down the affected platforms and is investigating with external experts, law enforcement, and regulators.
  • ASOS told customers: “Our teams, supported by external experts, have undertaken a detailed investigation over the last 48 hours.”
The ASOS warehouse seen from Darfield.
The ASOS warehouse seen from Darfield.

Photo: Steve Fareham, CC BY-SA 2.0, via Wikimedia Commons

What remains unknown

  • Scale: ASOS has not published a victim count. Attacker claims of “millions” of records are unverified — treat any number circulating as an attacker claim until ASOS or a regulator publishes one.
  • The Snowflake angle: the attackers claimed they accessed an ASOS cloud data environment via “Simon AI, a platform built on Snowflake”. Snowflake separately denied any compromise of its platform. Report both; conclude neither as fact.
  • The full investigation is expected to take weeks, per ASOS. No UK ICO filing details were in the sources read.

Not the same as the August breach

This is separate from an earlier ASOS US breach disclosed in August 2026, which affected roughly 138,800 individuals and did involve financial information. Conflating the two is a real risk for readers: different month, different vector, different data.

What you can do

  • ASOS says passwords and payment data were not accessed, so a password reset is not required by the company — but anyone reusing an ASOS password elsewhere should change it on the other service.
  • Expect phishing: exposed names, addresses, emails, and phone numbers are tailor-made for targeted scams. Treat any message urging you to engage with ASOS “staff” on Telegram or similar channels as fraudulent.
  • If you receive the rogue app push notification again, do not follow its instructions; contact ASOS through its official channels.

Corrections: No corrections have been published for this article.

About the author

Graham Ellis is a HackedWire staff writer covering consumer security & privacy. More from Graham Ellis →

Breach alerts, verified

Get HackedWire’s verified breach coverage in your inbox. Subscribe to the newsletter →