"We discovered that an unauthorised party gained access to an ASOS employee account by impersonating a trusted contact to obtain log in credentials," reads an ASOS security notification shared with BleepingComputer.
ASOS confirms social engineering and credential theft
ASOS has attributed a recent data breach to a social engineering attack in which attackers stole an employee’s login credentials and used them to access information held on third‑party platforms the retailer uses. The company said the credentials were used to "access information on certain third‑party platforms used by ASOS," and that it "locked down the affected platforms" once the intrusion was discovered.
ASOS described the attacker’s method as impersonation of a trusted contact in order to obtain the employee’s credentials. The company reported it has opened an investigation and is working with external experts, law enforcement, and regulatory authorities.
Claims by "Xuanye Group" and the October 6 push notification
On October 6, 2026, ASOS customers received a push notification through the ASOS mobile app alleging customer data theft and urging company staff to engage with the sender on Telegram. The message came from an actor self‑identifying as "Xuanye Group," who claimed to have stolen customer data but stated that payment information had not been taken.
ASOS later issued a public statement on its website confirming it had suffered a data breach that "may have exposed some 'basic' personal information and contact details." The company’s public messaging has sought to separate payment and authentication data from the exposed material.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleData exposed — what ASOS has confirmed
In its latest update to customers, ASOS listed the categories of data it believes were exposed. Those categories are:
- Full names
- Contact details
- Certain non‑personal account‑related information
ASOS explicitly said that hackers did not access payment card information or account passwords. The retailer also stated that its website and app "were at all times, and continue to be, completely safe to use." In messaging to customers, ASOS wrote: "There is no action you need to take on your account," while also advising customers to "remain cautious of unexpected messages or calls claiming to be from ASOS."
To reinforce that guidance, ASOS reminded customers: "We will never ask you to share passwords, security codes or payment details through an unsolicited message or call."
Investigation, containment, and additional security steps
ASOS says it has locked down the platforms that were accessed and launched an ongoing investigation with the help of external specialists, law enforcement, and regulators. The company told customers it will publish further updates "if important findings emerge" as the probe continues.
ASOS also stated it has already taken steps to implement additional security measures intended to prevent similar incidents in future. BleepingComputer asked ASOS for a figure on how many customers were impacted; the publication did not receive a number.
What this means for ASOS customers, security teams, and regulators
ASOS customers: Follow the company’s advice to take no immediate account action but remain vigilant for unsolicited calls or messages. Customers should treat any unexpected requests for passwords, security codes, or payment details as suspicious given ASOS’s explicit warning that it will not solicit such information via unsolicited contact.
Security teams supporting ASOS: The incident underscores a breach pathway tied to third‑party platform access following credential theft through impersonation. Teams involved in the investigation will be focused on how credentials were obtained, the scope of third‑party exposure, and the effectiveness of the "additional security measures" ASOS says it has implemented.
Regulators and law enforcement: ASOS has already engaged law enforcement and regulatory authorities and indicated it will share further findings as the investigation proceeds. Regulators will likely be monitoring the company’s assessments of exposed categories and any disclosure about the number of affected customers.
The thread tying these facts together is straightforward: attackers obtained an employee credential by impersonating a trusted contact, used it to reach information on third‑party systems, and then publicly claimed possession of customer data. ASOS has contained the immediate access, affirmed that payment data and passwords were not taken, and promised further updates as its investigation continues. One concrete fact remains open — the number of customers affected — and ASOS has not provided a figure in response to queries.




