Research · Explainer
How to Verify a Data Breach: A Field Guide for Skeptics
An attacker’s claim is the start of an investigation, not its conclusion. This is the verification ladder HackedWire climbs before it calls a breach confirmed — worked through with the ASOS incident as the example.
Photo: Cybersecurity and Infrastructure Security Agency, Public domain, via Wikimedia Commons
Every week brings a new claim: a leak-site post, a Telegram boast, a push notification urging employees to defect. Some are real. Some are theater — inflated, recycled, or aimed at tanking a stock price. The difference between reporting and rumor-mongering is method. Here is ours.
The verification ladder
Confirmation is not one thing; it is a stack. Each rung is harder to fake than the last:
- Official company statement or customer notice. The strongest single signal. ASOS’s Oct 8 customer security notification named the vector, the data exposed, and what was not exposed — that specificity is what makes a notice usable.
- Regulator or attorney-general filings. Breach-notification filings and AG statements create a public record under penalty of law.
- Law-enforcement confirmation. FBI or equivalent agencies confirming an investigation, or court records surfacing charges.
- Independent researcher or journalist evidence. Data samples handed to reporters, forensic logs, or HaveIBeenPwned indexing breached addresses.
- Attacker claims. Unverified until one of the above corroborates them. Always labeled as allegations.
Attacker claims sit at the bottom for a reason: the claimant’s incentives run directly against accuracy. A group calling itself the “Xuanye Group” claimed millions of ASOS records; ASOS has not confirmed any count. Per privacyon.com: treat any number you see circulating as an attacker claim until ASOS or a regulator publishes one.
Worked example: the ASOS incident
On Oct 6, 2026, ASOS customers received rogue push notifications through the ASOS app claiming data theft. Two days later, ASOS confirmed a social-engineering attack: “We discovered that an unauthorised party gained access to an ASOS employee account by impersonating a trusted contact to obtain log in credentials,” the company said in its security notification, shared via BleepingComputer.
The notice named exposed data (full names, contact details, certain non-personal account information) and what was not accessed (no payment-card information, no account passwords). That asymmetry — confirming the bad while bounding the scope — is the hallmark of a usable disclosure.
Photo: U.S. Department of Homeland Security, Public domain, via Wikimedia Commons
Corroborate with independent channels
The ASOS case shows corroboration in action: the BBC received a data sample from the attackers on Oct 7 — an independent journalist with evidence in hand (Cyber Magazine). HaveIBeenPwned indexing has served the same function in other incidents, such as the PeopleSoft breaches, where 455,000 email addresses were indexed. A sample plus a company notice moves a story from “alleged” to “confirmed”; a leak-site post alone does not.
Watch for conflation
The October 2026 ASOS incident is separate from an earlier ASOS US breach disclosed in August 2026, which affected roughly 138,800 individuals and did involve financial information. Conflating the two is a real reader risk — mixing victim counts, data types, and timelines. Verify which incident a claim attaches to before repeating it.
Handle third-party claims with care
The ASOS attackers claimed access to a cloud data environment via “Simon AI, a platform built on Snowflake.” Snowflake separately denied any compromise of its platform. The correct move: report both statements, conclude neither as fact. A denial from the named third party does not disprove an attack, and an attacker claim does not prove one. Leave the ambiguity visible.
What this means for readers
- Big numbers from unknown accounts are theater until a company, regulator, court, or researcher with evidence says otherwise.
- A company notice that names the vector and bounds the exposure is the signal; vague reassurance is noise.
- Separate incidents with similar names before sharing anything — check dates and victim profiles.
- Use independent checks: HaveIBeenPwned for your own addresses, and reputable journalists with samples for the incident itself.
No corrections have been published for this article.