[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f-4OyTGwBhdnqOkOE3ul8qxf3FlbS_Rs4xvmrssQApl8":3},{"article":4,"iocs":45},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":27,"category":28,"article_tags":32},"37d9bb68-51c4-4555-8f80-85e273a07ebc","ASOS links data breach to social engineering attack, credential theft","asos-links-data-breach-to-social-engineering-attack-credential-theft-e7ebdb","ASOS is sending updates to affected customers about the cybersecurity incident it suffered earlier this week, confirming that hackers accessed some personal data. [...]","UK fashion retailer ASOS has confirmed a data breach resulting from a social engineering attack where hackers impersonated a trusted contact to steal an employee's login credentials. These credentials were then used to access personal data and contact details on third-party platforms, though payment information and passwords were not compromised. The company is working with external experts and law enforcement, and has implemented additional security measures.","ASOS confirms data breach due to social engineering attack and credential theft.","ASOS links data breach to social engineering attack, credential theft By Bill Toulas October 8, 2026 07:42 AM 0 UK fashion retailer ASOS confirmed that a recent data breach was caused by a social engineering attack in which hackers stole an employee’s login credentials and used them to access information on third-party platforms used by the company. \"We discovered that an unauthorised party gained access to an ASOS employee account by impersonating a trusted contact to obtain log in credentials,\" reads an ASOS security notification shared with BleepingComputer. \"Those credentials were then used to access information on certain third-party platforms used by ASOS.\" The company locked down the affected platforms and launched an investigation with support from external experts, law enforcement, and regulatory authorities. ASOS is a large UK-based online fashion retailer that sells clothing, footwear, accessories, and beauty products to customers worldwide. On October 6, 2026, ASOS customers received a push notification through the ASOS app on their mobile devices, alleging customer data theft and urging the company’s staff to engage with them on Telegram. Malicious ASOS in-app notifications sent by hackers The threat actor, calling themselves “Xuanye Group,” claimed that they had stolen customer data, but not payment information. ASOS eventually confirmed via a statement published on its website that it had suffered a data breach that may have exposed some “basic” personal information and contact details. The latest update sent to customers confirms that the following details were exposed: Full names Contact details Certain non-personal account-related information ASOS says hackers did not access payment card information or account passwords. The retail giant also says its website and app were at all times, and continue to be, completely safe to use. “There is no action you need to take on your account,” ASOS says in its message to customers. “However, please remain cautious of unexpected messages or calls claiming to be from ASOS.” “We will never ask you to share passwords, security codes or payment details through an unsolicited message or call.” ASOS says its investigation is still underway, and it will share more updates if important findings emerge. The company also assured that it has already taken steps to implement additional security measures to prevent similar incidents in the future. BleepingComputer has asked ASOS about the number of customers impacted by this incident, but we have not received a figure yet. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat Related Articles: Advantest confirms personal information stolen in ransomware attackLACMA data breach last year exposed social security and medical dataASOS confirms data breach after “HACKED” in-app notificationsTimes Car confirms data breach affecting 6.6 million user accountsBigCommerce alerts merchants of data breach linked to Ribon apps","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fasos-links-data-breach-to-social-engineering-attack-credential-theft\u002F","https:\u002F\u002Fwww.bleepstatic.com\u002Fcontent\u002Fhl-images\u002F2026\u002F10\u002F06\u002Fasos-logo.jpg","2026-10-08T11:42:46+00:00","2026-10-08T12:00:09.139442+00:00",7,[18,21,24],{"name":19,"type":20},"ASOS","vendor",{"name":22,"type":23},"Xuanye Group","threat_actor",{"name":25,"type":26},"social engineering","technology","2e06f76c-d5b9-4f54-9eef-4d3447b10730",{"id":27,"icon":29,"name":30,"slug":31},null,"Breaches","breaches",[33,38,40],{"category":34},{"id":35,"icon":29,"name":36,"slug":37},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":39},{"id":27,"icon":29,"name":30,"slug":31},{"category":41},{"id":42,"icon":29,"name":43,"slug":44},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[46],{"type":47,"value":22,"context":48},"malware","Threat actor claiming responsibility for the attack"]